Input fields allowing special characters and scripts

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      There are various fields in Jenkins which accept special characters like <script>alert(1)</script> tags or java script content. These may result into the possible XSS attacks.

      Example in Credentials plug-in.

      Request to provide solution.

            Assignee:
            Unassigned
            Reporter:
            Ankur
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: