Description
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-1870
Related Vulnerabilities
CVE-2020-1958 Vulnerability in maven package org.apache.druid.extensions:druid-basic-security
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-impl
CVE-2022-34190 Vulnerability in maven package eu.markov.jenkins.plugin.mvnmeta:maven-metadata-plugin
CVE-2013-4322 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2014-2858 Vulnerability in maven package org.grails:grails-resources