Description
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Remediation
References
https://jenkins.io/security/advisory/2018-07-18/#SECURITY-944
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2020-2261 Vulnerability in maven package org.jenkins-ci.plugins:perfecto
CVE-2023-25822 Vulnerability in maven package com.epam.reportportal:service-api
CVE-2023-37908 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-xml
CVE-2022-23505 Vulnerability in npm package passport-wsfed-saml2
CVE-2010-1632 Vulnerability in maven package org.apache.axis2:axis2