Jenkins Project Inheritance Plugin vulnerable to cross site scripting
High severity
GitHub Reviewed
Published
Jul 1, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Package
Affected versions
<= 21.04.03
Patched versions
None
Description
Published by the National Vulnerability Database
Jun 30, 2022
Published to the GitHub Advisory Database
Jul 1, 2022
Reviewed
Dec 9, 2022
Last updated
Feb 2, 2023
Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
References