Description
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
Remediation
References
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1490
http://www.openwall.com/lists/oss-security/2019/10/23/2
http://packetstormsecurity.com/files/155200/Jenkins-Build-Metrics-1.3-Cross-Site-Scripting.html
Related Vulnerabilities
CVE-2022-41936 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2022-28220 Vulnerability in maven package org.apache.james:james-server-protocols-imap4
CVE-2023-1370 Vulnerability in maven package net.minidev:json-smart
CVE-2020-2167 Vulnerability in maven package com.openshift.jenkins:openshift-pipeline
CVE-2016-8735 Vulnerability in maven package org.apache.tomcat:tomcat-catalina-jmx-remote