Description
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/06/03/3
https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1726
Related Vulnerabilities
CVE-2021-26117 Vulnerability in maven package org.apache.activemq:artemis-server
CVE-2023-40341 Vulnerability in maven package io.jenkins.blueocean:blueocean
CVE-2020-15123 Vulnerability in npm package codecov
CVE-2019-5479 Vulnerability in npm package larvitbase-api
CVE-2023-35165 Vulnerability in npm package @aws-cdk/aws-eks