Description
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2858
Related Vulnerabilities
CVE-2020-11998 Vulnerability in maven package org.apache.activemq:activemq-broker
CVE-2011-5062 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2015-5167 Vulnerability in maven package org.apache.ranger:ranger
CVE-2023-29234 Vulnerability in maven package org.apache.dubbo:dubbo
CVE-2022-34183 Vulnerability in maven package io.jenkins.plugins:agent-server-parameter