Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability.
CPE | Name | Operator | Version |
---|---|---|---|
aws_codecommit_trigger | le | 3.0.12 |