Stored Cross-site Scripting vulnerability in Jenkins Extended Choice Parameter Plugin
        
  High severity
        
          GitHub Reviewed
      
        Published
          Mar 16, 2022 
          to the GitHub Advisory Database
          •
          Updated Feb 2, 2023 
      
  
Package
Affected versions
<= 346.vd87693c5a
  Patched versions
None
  Description
        Published by the National Vulnerability Database
      Mar 15, 2022 
    
  
        Published to the GitHub Advisory Database
      Mar 16, 2022 
    
  
        Reviewed
      Nov 30, 2022 
    
  
        Last updated
      Feb 2, 2023 
    
  
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
References