Description
Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1914
http://www.openwall.com/lists/oss-security/2020/09/16/3
Related Vulnerabilities
CVE-2023-41327 Vulnerability in maven package org.wiremock:wiremock-webhooks-extension
CVE-2015-5298 Vulnerability in maven package org.jenkins-ci.plugins:google-login
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_2.13
CVE-2021-3503 Vulnerability in maven package org.wildfly:wildfly-metrics
CVE-2024-22207 Vulnerability in npm package @fastify/swagger-ui