Description
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1676
Related Vulnerabilities
CVE-2020-7673 Vulnerability in npm package node-extend
CVE-2020-7021 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2020-26870 Vulnerability in npm package dompurify
CVE-2021-20220 Vulnerability in maven package io.undertow:undertow-core
CVE-2021-23331 Vulnerability in maven package com.squareup:connect