Description
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/07/02/7
https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1728%20%282%29
Related Vulnerabilities
CVE-2019-10746 Vulnerability in npm package mixin-deep
CVE-2020-6427 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-1003072 Vulnerability in maven package org.jenkins-ci.plugins:wildfly-deployer
CVE-2022-41254 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2019-16777 Vulnerability in maven package org.webjars.npm:bin-links