Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2020-2207 Vulnerability in maven package org.jenkins-ci.plugins:vncviewer
CVE-2016-0792 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-5786 Vulnerability in npm package electron
CVE-2020-2170 Vulnerability in maven package org.jenkins-ci.plugins:rapiddeploy-jenkins
CVE-2021-40143 Vulnerability in maven package org.sonatype.nexus:nexus-repository