Description
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-1870
Related Vulnerabilities
CVE-2011-2732 Vulnerability in maven package org.springframework.security:spring-security-web
CVE-2020-17150 Vulnerability in npm package typescript-tslint-plugin
CVE-2023-32313 Vulnerability in npm package vm2
CVE-2023-22457 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-ui
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:api-ldap-client-all