CVE-2017-1000404
26.01.2018, 02:29
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.
Vendor | Product | Version |
---|---|---|
jenkins | delivery_pipeline | 𝑥 ≤ 1.0.7 |
𝑥
= Vulnerable software versions