CVE-2019-16564
17.12.2019, 15:15
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.
Vendor | Product | Version |
---|---|---|
jenkins | pipeline_aggregator_view | 𝑥 ≤ 1.8 |
𝑥
= Vulnerable software versions