Description
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/06/03/3
https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1726
Related Vulnerabilities
CVE-2020-9488 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2022-43407 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-input-step
CVE-2019-16775 Vulnerability in npm package bin-links
CVE-2023-22946 Vulnerability in maven package org.apache.spark:spark-core_2.12
CVE-2021-28169 Vulnerability in maven package org.eclipse.jetty:jetty-servlets