Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
2022-04-12T20:15:09.080
2024-11-21T06:58:22.993
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | credentials | < 2.6.1.1 | Yes |
Application | jenkins | credentials | < 1074.1076.v39c30cecb_0e2 | Yes |
Application | jenkins | credentials | < 1112.vc87b_7a_3597f6 | Yes |