Jenkins Dashboard View Plugin vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 20, 2023
Package
Affected versions
< 2.12
Patched versions
2.12
Description
Published by the National Vulnerability Database
Sep 12, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Mar 2, 2023
Last updated
Dec 20, 2023
Dashboard View Plugin did not escape the build description on the Latest Builds View. This resulted in a cross-site scripting vulnerability exploitable by attackers able to control the description of builds shown on that view.
Dashboard View Plugin now applies the configured markup formatter to the build description, rendering it as it appears elsewhere in Jenkins.
References