Security Advisory

CVE-2018-1000416

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-01-09 23:00:00
Last updated 2024-08-05 12:40:47
Assigner mitre
State PUBLISHED

Description

A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.