Description
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1676
Related Vulnerabilities
CVE-2021-32691 Vulnerability in npm package data-connector-rock
CVE-2022-35278 Vulnerability in maven package org.apache.activemq:artemis-web
CVE-2022-2048 Vulnerability in maven package org.eclipse.jetty.http2:http2-server
CVE-2022-28889 Vulnerability in maven package org.apache.druid:druid
CVE-2021-41182 Vulnerability in maven package org.webjars.npm:jquery-ui