Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the checkVncServ
form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.
CPE | Name | Operator | Version |
---|---|---|---|
vncrecorder | le | 1.25 |