job parameters use <f:entry description> without using the configured markup formatter. This allows to inject arbitrary html into the build form.

          [JENKINS-18427] parameter description don't use MarkupFormatter

          Nicolas De Loof created issue -
          SCM/JIRA link daemon made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Resolved [ 5 ]
          Nicolas De Loof made changes -
          Labels New: lts-candidate
          Jesse Glick made changes -
          Labels Original: lts-candidate New: lts-candidate security
          Oliver Gondža made changes -
          Labels Original: lts-candidate security New: lts-1.509.3-fixed security
          Oliver Gondža made changes -
          Labels Original: lts-1.509.3-fixed security New: 1.509.3-fixed security
          Daniel Beck made changes -
          Link New: This issue is related to JENKINS-21855 [ JENKINS-21855 ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 149734 ] New: JNJira + In-Review [ 193267 ]

            Unassigned Unassigned
            ndeloof Nicolas De Loof
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: