Cross-site scripting in search box

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Hudson 1.295 allows user to type cross-site scriptings(xss) on search-box.
      Example:
      http://hudson-host/search/?
      q=<script>alert('script');</script>&json={"q":+"<script>alert('oops');</script>"
      }

            Assignee:
            Kohsuke Kawaguchi
            Reporter:
            danielvs
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: