Description
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.
Remediation
References
https://jenkins.io/security/advisory/2020-04-07/#SECURITY-1769
http://www.openwall.com/lists/oss-security/2020/04/07/3
Related Vulnerabilities
CVE-2018-11804 Vulnerability in maven package org.apache.spark:spark-core_2.10
CVE-2022-29253 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2020-2269 Vulnerability in maven package org.jenkins-ci.plugins:chosen-views-tabbar
CVE-2017-1000427 Vulnerability in maven package org.webjars.bower:marked
CVE-2022-39263 Vulnerability in npm package @next-auth/upstash-redis-adapter