Description
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descriptions.
Remediation
References
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1591
http://www.openwall.com/lists/oss-security/2019/12/17/1
Related Vulnerabilities
CVE-2022-23510 Vulnerability in npm package @cubejs-backend/api-gateway
CVE-2020-11990 Vulnerability in npm package cordova-plugin-camera
CVE-2022-4742 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2022-3145 Vulnerability in npm package @okta/oidc-middleware
CVE-2023-34610 Vulnerability in maven package com.cedarsoftware:json-io