Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Recipe Card Blocks for Gutenberg & Elementor Cross-Site Scripting (2.8.0)
MySQL CVE-2012-2750 Vulnerability (CVE-2012-2750)
Oracle Database Server CVE-2007-2115 Vulnerability (CVE-2007-2115)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2018-12022)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7572)