Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4220)
TYPO3 Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-36104)
WordPress Plugin WordPress Photo Gallery by Gallery Bank Cross-Site Scripting (3.0.69)
UAParser.js Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2021-4229)