Description
Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2098
Related Vulnerabilities
CVE-2023-31579 Vulnerability in maven package top.tangyh.basic:lamp-core
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-syntax-html5
CVE-2023-49382 Vulnerability in maven package com.jfinal:jfinal
CVE-2011-2712 Vulnerability in maven package org.apache.wicket:wicket
CVE-2023-25653 Vulnerability in maven package org.webjars.npm:node-jose