Description
Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2098
Related Vulnerabilities
CVE-2020-16044 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-5404 Vulnerability in maven package io.projectreactor.netty:reactor-netty
CVE-2015-0254 Vulnerability in maven package org.apache.taglibs:taglibs-standard
CVE-2018-15531 Vulnerability in maven package net.bull.javamelody:javamelody-core
CVE-2019-1003041 Vulnerability in maven package org.jenkins-ci.plugins:script-security