Description
A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, resulting in a reflected XSS vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1724
Related Vulnerabilities
CVE-2023-37954 Vulnerability in maven package com.sonyericsson.hudson.plugins.rebuild:rebuild
CVE-2022-25345 Vulnerability in npm package @discordjs/opus
CVE-2021-37305 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2021-33605 Vulnerability in maven package com.vaadin:vaadin-checkbox-flow
CVE-2022-46907 Vulnerability in maven package org.apache.jspwiki:jspwiki-war