Description
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.
Remediation
References
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-04-11
Related Vulnerabilities
CVE-2021-3644 Vulnerability in maven package org.wildfly.core:wildfly-controller
CVE-2014-3623 Vulnerability in maven package org.apache.wss4j:wss4j-ws-security-dom
CVE-2021-21165 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-9497 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2014-0227 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core