Description
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/31/1
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1184
Related Vulnerabilities
CVE-2020-8116 Vulnerability in maven package org.webjars.npm:dot-prop
CVE-2020-10693 Vulnerability in maven package org.hibernate:hibernate-validator
CVE-2021-31408 Vulnerability in maven package com.vaadin:flow-client
CVE-2022-36904 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector
CVE-2021-41183 Vulnerability in maven package org.webjars.bower:jquery-ui