GHSA-g66m-fqxf-3w35
HIGHCVE-2022-43407Pipeline: Input Step Plugin 451.vf1aa4f405289 and earlier does not restrict or sanitize the optionally specified ID of the input step. This ID is used for the URLs that process user interactions for the given input step (proceed or abort) and is not correctly encoded.
- Affected
- < 456.vd8a
- Fixed in
- 456.vd8a_957db_5b_e9
- Weakness
- CWE-352
- Published
- 2022-10-19
- Source
- github