GHSA-g364-c7w5-93wh
MODERATECVE-2017-1000404The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs. Version 1.0.8 of the plugin converts the value to a boolean (true/false) and inserts that into the page instead.
- Affected
- <= 1.0.7
- Fixed in
- 1.0.8
- Weakness
- CWE-79
- Published
- 2022-05-14
- Source
- github