Description
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin Theme Check Cross-Site Request Forgery (20190208.1)
Joomla! Core Information Disclosure (1.5.0 - 3.7.5)
WordPress Plugin BestSmallShopLite Cross-Site Scripting (1.0.1)
MySQL CVE-2012-0487 Vulnerability (CVE-2012-0487)
WordPress Plugin Social Share Icons & Social Share Buttons Cross-Site Scripting (3.0.5)