The following flaw was found in Jenkins: Jenkins allows the creation of users with less-than and greater-than characters in their names. These user names were not escaped when displaying search suggestions, resulting in a cross-site scripting vulnerability. External References: https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2017-02-01 Upstream patch: https://github.com/jenkinsci/jenkins/commit/307ed31caba68a46426b8c73a787a05add2c7489
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1418736]