Description
Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/07/02/7
https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1776
Related Vulnerabilities
CVE-2022-42466 Vulnerability in maven package org.apache.isis.commons:isis-commons
CVE-2020-6426 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-41561 Vulnerability in maven package org.apache.parquet:parquet
CVE-2021-21294 Vulnerability in maven package org.http4s:http4s-blaze-server_2.12