MEDIUM
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin
Published Sep 23, 2020
5.4
MEDIUMCVSS 3.1
EPSS 0.73%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.