-
CVSS Score
-The vulnerability stems from unescaped display of file names in HTML contexts. Jenkins plugins typically use Jelly templates for UI rendering and Java classes for data handling. The combination of:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.main:associated-files-plugin | maven | <= 0.2.1 |