Description
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2022-12-07/#SECURITY-2869
Related Vulnerabilities
CVE-2017-1000118 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.11
CVE-2021-21122 Vulnerability in npm package electron
CVE-2020-13940 Vulnerability in maven package org.apache.nifi:nifi-bootstrap
CVE-2013-2254 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2023-31126 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml