-
CVSS Score
-The vulnerability stems from unescaped Jelly template variables in tooltip attributes. The commit diff shows three critical changes where h.xmlEscape() was added to sanitize user-controlled values:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:matrix-project | maven | <= 1.16 | 1.17 |
Ongoing coverage of React2Shell