Description
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.
Remediation
References
https://jenkins.io/security/advisory/2017-11-08/
http://www.securityfocus.com/bid/102826
http://www.securityfocus.com/bid/101773
Related Vulnerabilities
CVE-2022-36033 Vulnerability in maven package org.jsoup:jsoup
CVE-2023-41080 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-main
CVE-2013-2254 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2022-44729 Vulnerability in maven package org.apache.xmlgraphics:batik-transcoder