Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-1889
Related Vulnerabilities
CVE-2020-2308 Vulnerability in maven package org.csanchez.jenkins.plugins:kubernetes
CVE-2018-1000610 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2023-2196 Vulnerability in maven package org.jenkins-ci.plugins:codedx
CVE-2022-43407 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-input-step
CVE-2022-1274 Vulnerability in maven package org.keycloak:keycloak-themes