Description
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.
Remediation
References
https://jenkins.io/security/advisory/2020-04-07/#SECURITY-1769
http://www.openwall.com/lists/oss-security/2020/04/07/3
Related Vulnerabilities
CVE-2019-5432 Vulnerability in npm package mqtt-packet
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee9:jetty-ee9-servlets
CVE-2019-10335 Vulnerability in maven package org.jenkins-ci.plugins:electricflow
CVE-2022-25644 Vulnerability in npm package @pendo324/get-process-by-name
CVE-2022-41340 Vulnerability in npm package @lionello/secp256k1-js