Description
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-2903
Related Vulnerabilities
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2019-20365 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2020-13947 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2016-4567 Vulnerability in maven package org.webjars.bower:mediaelement
CVE-2013-1879 Vulnerability in maven package activemq:activemq-core