Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1781
Related Vulnerabilities
CVE-2022-29599 Vulnerability in maven package org.apache.maven.shared:maven-shared-utils
CVE-2021-27807 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2023-28155 Vulnerability in maven package org.webjars:request
CVE-2020-7691 Vulnerability in maven package org.webjars.npm:jspdf
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service-api