Description
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1907
Related Vulnerabilities
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-service
CVE-2023-37946 Vulnerability in maven package org.openshift.jenkins:openshift-login
CVE-2023-26031 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-project
CVE-2023-49803 Vulnerability in npm package @koa/cors
CVE-2022-31160 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui