Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.
| Software | From | Fixed in |
|---|---|---|
| jenkins / credentials | - | 2.3.18.x |
org.jenkins-ci.plugins / credentials
|
- | 2.3.19 |