Description
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy WP SMTP PHP Object Injection (1.3.9)
WordPress Other Vulnerability (CVE-2006-1012)
MySQL CVE-2024-21200 Vulnerability (CVE-2024-21200)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4400)
osTicket Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-24881)