Ant plugin failed to escape tool names it shows on job configuration screens, resulting in a cross-site scripting (XSS) vulnerability that is exploitable only by Jenkins administrators. Affects versions up to and including 1.7. External References: https://jenkins.io/security/advisory/2018-01-22/
Created jenkins-ant-plugin tracking bugs for this issue: Affects: fedora-all [bug 1537191]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.