Description
Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/09/1
https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1784
Related Vulnerabilities
CVE-2022-36884 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2021-23328 Vulnerability in npm package iniparserjs
CVE-2014-9772 Vulnerability in npm package validator
CVE-2022-1471 Vulnerability in maven package org.yaml:snakeyaml
CVE-2019-10362 Vulnerability in maven package io.jenkins:configuration-as-code