Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-1889
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.webjars.bower:bootstrap
CVE-2018-1000055 Vulnerability in maven package org.jvnet.hudson.plugins:android-lint
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:jasper
CVE-2022-34786 Vulnerability in maven package org.jenkins-ci.plugins:rich-text-publisher-plugin
CVE-2018-14042 Vulnerability in maven package org.webjars.bower:bootstrap-sass