Description
Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to workspaces and archived artifacts.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2008-0343 Vulnerability (CVE-2008-0343)
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4464)
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2005-0227)
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2044)