Description
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1676
Related Vulnerabilities
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2022-36313 Vulnerability in maven package org.webjars.npm:file-type
CVE-2020-28847 Vulnerability in npm package valine
CVE-2022-22984 Vulnerability in npm package snyk-mvn-plugin
CVE-2022-1291 Vulnerability in maven package org.webjars.npm:tableexport.jquery.plugin