Cross-Site Scripting Vulnerability in Jenkins Delivery Pipeline Plugin

Cross-Site Scripting Vulnerability in Jenkins Delivery Pipeline Plugin

CVE-2017-1000404 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.

Learn more about our Web Application Penetration Testing UK.