もっと詳しく

A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in

RebuildAction/BooleanParameterValue.jelly,  
RebuildAction/ExtendedChoiceParameterValue.jelly,  
RebuildAction/FileParameterValue.jelly,  
RebuildAction/LabelParameterValue.jelly,  
RebuildAction/ListSubversionTagsParameterValue.jelly,  
RebuildAction/MavenMetadataParameterValue.jelly,  
RebuildAction/NodeParameterValue.jelly,  
RebuildAction/PasswordParameterValue.jelly,  
RebuildAction/RandomStringParameterValue.jelly,  
RebuildAction/RunParameterValue.jelly,  
RebuildAction/StringParameterValue.jelly,  
RebuildAction/TextParameterValue.jelly,  
RebuildAction/ValidatingStringParameterValue.jelly  

that allows users with Job/Configuration permission to insert arbitrary HTML into rebuild forms.

References