Description
Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2768
Related Vulnerabilities
CVE-2020-16041 Vulnerability in npm package electron
CVE-2016-5019 Vulnerability in maven package org.apache.myfaces.trinidad:trinidad-impl
CVE-2022-2053 Vulnerability in maven package io.undertow:undertow-core
CVE-2021-41079 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-2161 Vulnerability in maven package org.jenkins-ci.main:jenkins-core