Description
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.
Remediation
References
https://jenkins.io/security/advisory/2017-11-16/
http://www.securityfocus.com/bid/101927
Related Vulnerabilities
CVE-2021-32012 Vulnerability in npm package xlsx
CVE-2020-12827 Vulnerability in npm package mjml
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk14
CVE-2021-43797 Vulnerability in maven package io.netty:netty-codec-http
CVE-2023-33004 Vulnerability in maven package org.jenkins-ci.plugins:tag-profiler