Lucene search

K
osvGoogleOSV:GHSA-RP4X-H577-CHVQ
HistoryMay 24, 2022 - 7:20 p.m.

Stored XSS vulnerability in Jenkins Active Choices Plugin

2022-05-2419:20:32
Google
osv.dev
4

0.001 Low

EPSS

Percentile

22.3%

Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

Jenkins Active Choices Plugin 2.5.7 escapes references to parameter names.

0.001 Low

EPSS

Percentile

22.3%