GHSA-g364-c7w5-93wh
Dashboard / Vulnerabilities / GHSA-g364-c7w5-93wh
Summary: Jenkins Delivery Pipeline Plugin Cross-site Scripting vulnerability
Details: The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs. Version 1.0.8 of the plugin converts the value to a boolean (true/false) and inserts that into the page instead.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000404, https://jenkins.io/security/advisory/2017-11-16, http://www.securityfocus.com/bid/101927
Affected packages
Package
Name: se.diabol.jenkins.pipeline:delivery-pipeline-plugin
Purl: pkg:maven/se.diabol.jenkins.pipeline/delivery-pipeline-plugin
Affected ranges
Type: ECOSYSTEM
Events:
