Description
Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2768
Related Vulnerabilities
CVE-2020-6423 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-21696 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-12540 Vulnerability in maven package io.vertx:vertx-web
CVE-2017-4960 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2023-0868 Vulnerability in maven package org.opennms:opennms-webapp