Description
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/04/07/3
https://jenkins.io/security/advisory/2020-04-07/#SECURITY-1769
Related Vulnerabilities
CVE-2020-8132 Vulnerability in npm package pdf-image
CVE-2019-10749 Vulnerability in npm package sequelize
CVE-2023-34478 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2021-21661 Vulnerability in maven package org.jenkins-ci.plugins:kubernetes-cli