Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin A. Gallery TimThumb Arbitrary File Upload (0.9rev378511)
WordPress Plugin Simple Membership Cross-Site Scripting (3.2.8)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-26071)
WordPress Plugin WP-HR Manager:The Human Resources Unspecified Vulnerability (2.9.4)
Apache HTTP Server Numeric Errors Vulnerability (CVE-2010-0010)