Required CVE Record Information
Description
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the content of these files to attack Jenkins users.
References 1 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.