Description
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Favorite Posts Cross-Site Scripting (1.6.5)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2021-3629)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1578)
WordPress Plugin Custom Metas Cross-Site Scripting (1.5.1)
WordPress Plugin Share This Image Cross-Site Scripting (1.03)