A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.6wind.jenkins:lockable-resources(Maven) | 0 | 2.5 | N/A |
CVSS Metrics