Description
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Remediation
References
https://jenkins.io/security/advisory/2016-06-20/
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-06-20
Related Vulnerabilities
CVE-2015-7499 Vulnerability in npm package libxmljs
CVE-2020-11972 Vulnerability in maven package org.apache.camel:camel-rabbitmq
CVE-2014-3667 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-37277 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2020-2243 Vulnerability in maven package org.jenkins-ci.plugins:vmanager-plugin