Jenkins Generic Webhook Trigger... CVE-2022-25185

3.5 AV AC AU C I A
发布: 2022-02-15
修订: 2024-11-21

Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息