A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in
RebuildAction/BooleanParameterValue.jelly,
RebuildAction/ExtendedChoiceParameterValue.jelly,
RebuildAction/FileParameterValue.jelly,
RebuildAction/LabelParameterValue.jelly,
RebuildAction/ListSubversionTagsParameterValue.jelly,
RebuildAction/MavenMetadataParameterValue.jelly,
RebuildAction/NodeParameterValue.jelly,
RebuildAction/PasswordParameterValue.jelly,
RebuildAction/RandomStringParameterValue.jelly,
RebuildAction/RunParameterValue.jelly,
RebuildAction/StringParameterValue.jelly,
RebuildAction/TextParameterValue.jelly,
RebuildAction/ValidatingStringParameterValue.jelly
that allows users with Job/Configuration permission to insert arbitrary HTML into rebuild forms.
{ "nvd_published_at": "2019-01-09T23:29:00Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-11-03T19:12:53Z" }