CVE-2017-1000404

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/01/2018
Last modified:
08/02/2018

Description

The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:delivery_pipeline:*:*:*:*:*:jenkins:*:* 1.0.7 (including)