Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
| Software | From | Fixed in |
|---|---|---|
| jenkins / git | - | 4.2.0.x |
org.jenkins-ci.plugins / git
|
- | 4.2.1 |