Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.

Product Status

Learn more

Versions 1 Total

Default Status: unaffected

affected

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.

Authorized Data Publishers