Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin File Manager Advanced Shortcode Directory Traversal (2.4)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-5688)
WordPress Plugin RSS Includes Pages Unspecified Vulnerability (3.1)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5865)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-3809)