- Inscrit
- 29 Octobre 2025
- Messages
- 5 962
- Réactions
- 1
- Points
- 38
Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security realm, or directly inside Jenkins.
Source :
Posté automatiquement par le Bot FreelandForum.
Source :
You must be registered for see links
Posté automatiquement par le Bot FreelandForum.