Description
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin MyLiveChat-Free Live Chat Plugin for WordPress Cross-Site Scripting (2.0.1)
WordPress Plugin WP Frontend Profile Security Bypass (1.2.1)
WordPress Plugin HTML5 Maps Cross-Site Request Forgery (1.6.5.6)
WordPress Plugin Simple Security Multiple Cross-Site Scripting Vulnerabilities (1.1.5)
WordPress Plugin Tickera-WordPress Event Ticketing Cross-Site Request Forgery (3.4.9.9)