Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1781
Related Vulnerabilities
CVE-2021-23381 Vulnerability in npm package killing
CVE-2021-23400 Vulnerability in npm package nodemailer
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2020-6428 Vulnerability in npm package electron
CVE-2020-11112 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind