Timestamper Plugin 1.11.1 and earlier does not escape or sanitize the HTML formatting used to display the timestamps in console output for builds.
This results in a stored cross-site scripting vulnerability that can be exploited by users with Overall/Administer permission.
Timestamper Plugin 1.11.2 sanitizes the HTML formatting for timestamps and only allows basic, safe HTML formatting.
{
"nvd_published_at": "2020-03-09T16:15:00Z",
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2023-01-05T20:18:11Z",
"severity": "MODERATE",
"github_reviewed": true
}