Description
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Remediation
References
https://jenkins.io/security/advisory/2018-05-09/#SECURITY-821
Related Vulnerabilities
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-spark-engine
CVE-2021-22144 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2017-1000389 Vulnerability in maven package org.jenkins-ci.plugins:plugin
CVE-2021-21614 Vulnerability in maven package org.jenkins-ci.plugins:bumblebee
CVE-2016-2175 Vulnerability in maven package org.apache.pdfbox:pdfbox