Description
Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2168
Related Vulnerabilities
CVE-2023-30609 Vulnerability in npm package matrix-react-sdk
CVE-2018-1270 Vulnerability in maven package org.springframework:spring-messaging
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main
CVE-2019-1003088 Vulnerability in maven package egor-n:fabric-beta-publisher
CVE-2023-40176 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates