-
Bug
-
Resolution: Fixed
-
Critical
-
None
One of our developers set their username so this was in the config:
<?xml version='1.0' encoding='UTF-8'?>
<user>
<fullName>First Last </a></td><td></td><td>1000000.0</td></tr><tr><td><a href="www.bbc.co.uk"></fullName>
This could be used for evil javascript injection purposes as well as silly ones.
- is related to
-
JENKINS-5135 Adopt <?jelly escape-by-default='true'?> everywhere
- Resolved