MEDIUM
Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission
Published Oct 8, 2020
5.4
MEDIUMCVSS 3.1
EPSS 0.90%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.