-
Bug
-
Resolution: Fixed
-
Major
job parameters use <f:entry description> without using the configured markup formatter. This allows to inject arbitrary html into the build form.
- is related to
-
JENKINS-21855 Add markup formatter preview for parameter descriptions
-
- Resolved
-
Code changed in jenkins
User: Nicolas De Loof
Path:
changelog.html
core/src/main/java/hudson/model/ParameterDefinition.java
core/src/main/resources/hudson/model/StringParameterDefinition/index.jelly
war/src/main/webapp/scripts/hudson-behavior.js
http://jenkins-ci.org/commit/jenkins/0449e79c0e760438eb59967bbe8b145f68e8974b
Log:
[FIXED JENKINS-18427] use MarkupFormater