Description
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
http://osvdb.org/100106
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-11-20
http://secunia.com/advisories/55783
https://wiki.jenkins-ci.org/display/JENKINS/Build+Failure+Analyzer
Related Vulnerabilities
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-server
CVE-2019-10449 Vulnerability in maven package org.jenkins-ci.plugins:fortify-on-demand-uploader
CVE-2022-22931 Vulnerability in maven package org.apache.james:james-server
CVE-2023-37911 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2019-11777 Vulnerability in maven package org.eclipse.paho:org.eclipse.paho.client.mqttv3