Description
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Affected products
- Jenkins Project / Jenkins Matrix Project Pluginunspecified – 1.19
- Jenkins Project / Jenkins Matrix Project Plugin1.18.1 – 1.18.1