Description
A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Remediation
References
https://jenkins.io/security/advisory/2018-06-25/#SECURITY-906
Related Vulnerabilities
CVE-2021-41079 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-6532 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-49299 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2018-1316 Vulnerability in maven package org.apache.ode:ode-axis2
CVE-2009-2901 Vulnerability in maven package tomcat:catalina