Description
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3472)
Squid Uncontrolled Recursion Vulnerability (CVE-2023-50269)
WordPress Plugin Ultimate Addons for Elementor Security Bypass (1.20.0)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0791)
WordPress Plugin Clipta Video Informer Cross-Site Scripting (1.0)