OSV 1.4.0 · github-reviewed · 修改于 2026-05-07 06:52
发布时间
2026-04-29 23:30
GitHub 审查时间
2026-05-07 06:52
NVD 发布时间
2026-04-29 22:16
源文件
advisories/github-reviewed/2026/04/GHSA-f8h4-46xv-h7jj/GHSA-f8h4-46xv-h7jj.json
Jenkins HTML Publisher Plugin versoins 427 and earlier do not escape the job name and URL in the legacy wrapper file.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
HTML Publisher Plugin 427.1 escapes job name and URL when generating the legacy wrapper file.