Lucene search

K
osvGoogleOSV:GHSA-GP7C-XMMM-7PQR
HistoryApr 13, 2022 - 12:00 a.m.

Stored Cross-site Scripting vulnerabilities in Jenkins Extended Choice Parameter Plugin

2022-04-1300:00:18
Google
osv.dev
10

0.001 Low

EPSS

Percentile

22.0%

Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

0.001 Low

EPSS

Percentile

22.0%