Description
Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-2892
Related Vulnerabilities
CVE-2023-24429 Vulnerability in maven package org.jenkins-ci.plugins:semantic-versioning-plugin
CVE-2020-7961 Vulnerability in maven package com.liferay.portal:portal-impl
CVE-2019-1003097 Vulnerability in maven package com.ds.tools.hudson:crowd
CVE-2021-20328 Vulnerability in maven package org.mongodb:mongodb-driver-sync
CVE-2019-17513 Vulnerability in maven package io.ratpack:ratpack-core