Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-23122

Cross-Site-Scripting (XSS) Vulnarability: Github Titles rendered unescaped to build description

    • Icon: Bug Bug
    • Resolution: Won't Fix
    • Icon: Major Major
    • ghprb-plugin
    • None

      When having a pull request title which contains quotes the title is put into the build description unescaped which actually allows XSS (e. g. execute a task in the name of a different user).

      At first glance it only corrupts the output:

            janinko Honza Brázdil
            thragor Mark Michaelis
            Votes:
            2 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: