Description
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.
Remediation
References
https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3244
http://www.openwall.com/lists/oss-security/2023/09/20/5
Related Vulnerabilities
CVE-2014-0050 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-standalone
CVE-2022-22143 Vulnerability in npm package convict
CVE-2022-29166 Vulnerability in npm package matrix-appservice-irc
CVE-2019-10475 Vulnerability in maven package org.jenkins-ci.plugins:build-metrics
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka