Lucene search

K
osvGoogleOSV:GHSA-H6QC-455M-7V6V
HistoryMay 24, 2022 - 5:23 p.m.

Stored XSS vulnerability in single axis builds tooltips in Jenkins Matrix Project Plugin

2022-05-2417:23:38
Google
osv.dev
8

0.001 Low

EPSS

Percentile

22.0%

Matrix Project Plugin 1.16 and earlier does not escape node names shown in tooltips on the overview page of builds with a single axis. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Agent/Configure permission.

Matrix Project Plugin 1.17 escapes the node names shown in these tooltips.

0.001 Low

EPSS

Percentile

22.0%