Description
Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2183
Related Vulnerabilities
CVE-2018-11778 Vulnerability in maven package org.apache.ranger:ranger
CVE-2020-1941 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2013-2248 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2015-2582 Vulnerability in maven package org.keycloak:keycloak-saml-core
CVE-2021-30179 Vulnerability in maven package org.apache.dubbo:dubbo