OSV 1.4.0 · github-reviewed · 修改于 2023-10-28 00:16
发布时间
2022-01-13 08:00
GitHub 审查时间
2022-04-29 12:37
NVD 发布时间
2022-01-13 04:15
源文件
advisories/github-reviewed/2022/01/GHSA-5qx5-vg5w-5mx3/GHSA-5qx5-vg5w-5mx3.json
Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.