MEDIUM
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties
Published Sep 12, 2019
5.4
MEDIUMCVSS 3.1
EPSS 0.69%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.