Special Character like the '+' character for single select param, will be escaped to HTML code

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Since Release 2.5 and implementation of SECURITY-2008 - CVE-2020-2290 we can't use the '+' character in our single select list.

      For example:

      We have a "Active Choises Parameter" with Choice Type "Single Select" to choose a version. Our versions have the format "<version>+build.<counter>".

      The "+" character will be escaped to "+".

       

      Is it possible, that this is a bug?

            Assignee:
            Bruno P. Kinoshita
            Reporter:
            Jens
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: