Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1781
Related Vulnerabilities
CVE-2020-35728 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-1003045 Vulnerability in maven package de.eacg:ecs-publisher
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-markdown-gfm
CVE-2020-16040 Vulnerability in npm package electron
CVE-2020-2113 Vulnerability in maven package org.jenkins-ci.tools:git-parameter