Description
Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2168
Related Vulnerabilities
CVE-2010-2227 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2023-49395 Vulnerability in maven package com.jfinal:jfinal
CVE-2012-4431 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2022-23848 Vulnerability in maven package org.alluxio:alluxio-logserver