Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer(Maven) | 0 | 1.27.1 | N/A |
CVSS Metrics