Lucene search

K
osvGoogleOSV:GHSA-WC2G-9J98-VCGW
HistoryMay 24, 2022 - 5:10 p.m.

Jenkins Subversion Release Manager Plugin vulnerable to cross-site scripting (XSS)

2022-05-2417:10:29
Google
osv.dev
8
jenkins
subversion
release manager
cross-site scripting
xss
vulnerability
repository url
form validation

EPSS

0.001

Percentile

36.1%

Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation. This results in a reflected cross-site scripting vulnerability that can also be exploited similar to a stored cross-site scripting vulnerability by users with Job/Configure permission.

EPSS

0.001

Percentile

36.1%

Related for OSV:GHSA-WC2G-9J98-VCGW