Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-64982

Special Character like the '+' character for single select param, will be escaped to HTML code

XMLWordPrintable

      Since Release 2.5 and implementation of SECURITY-2008 - CVE-2020-2290 we can't use the '+' character in our single select list.

      For example:

      We have a "Active Choises Parameter" with Choice Type "Single Select" to choose a version. Our versions have the format "<version>+build.<counter>".

      The "+" character will be escaped to "+".

       

      Is it possible, that this is a bug?

            kinow Bruno P. Kinoshita
            grossmane Jens
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: