-
CVSS Score
-The vulnerability stems from unescaped tooltip content in the l:helpIcon component's Jelly template. The commit diff shows the fix adds h.htmlAttributeEscape() to the tooltip attribute in helpIcon.jelly. The vulnerable code path is the rendering of the tooltip attribute in the l:icon component within this template, which didn't properly sanitize user-controllable input before insertion into HTML attributes.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core | maven | >= 2.367, < 2.370 | 2.370 |
A Semantic Attack on Google Gemini - Read the Latest Research