Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.22.24)
FrontAccounting Multiple SQL Injection Vulnerabilities (CVE-2014-3973)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2097)
Microsoft SQL Server Other Vulnerability (CVE-2002-0154)
WordPress Plugin Redirection HTTP Referrer Header HTML Injection (2.2.9)