Description
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1184
http://www.openwall.com/lists/oss-security/2019/07/31/1
Related Vulnerabilities
CVE-2020-7012 Vulnerability in npm package kibana
CVE-2019-17566 Vulnerability in maven package org.apache.xmlgraphics:batik-transcoder
CVE-2022-21721 Vulnerability in npm package next
CVE-2020-9281 Vulnerability in npm package ckeditor4-dev
CVE-2019-1003034 Vulnerability in maven package org.jenkins-ci.plugins:job-dsl