Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.
| Software | From | Fixed in |
|---|---|---|
| jenkins / git | - | 4.8.2.x |
org.jenkins-ci.plugins / git
|
- | 4.8.3 |