Description
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Remediation
References
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2013-4567)
Apache HTTP Server Other Vulnerability (CVE-2002-1233)
Oracle Database Server CVE-2014-4310 Vulnerability (CVE-2014-4310)
WordPress 4.7.x Arbitrary File Deletion Vulnerability (4.7 - 4.7.10)
WordPress Plugin Easy Contact Form Builder Cross-Site Scripting (1.0)