GHSA-43ph-42gv-7965MediumCVSS 5.5
Jenkins buildgraph-view Plugin does not escape the build URL
🔗 CVE IDs covered (1)
📋 Description
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.
As of publication of this advisory, there is no fix.
🎯 Affected products1
- maven/org.jenkins-ci.plugins:buildgraph-view:<= 1.8