CVE-2019-16563

Publication date

2019-12-17 14:40:51

Family

jenkins

State

PUBLISHED

Description

Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties.