Description
Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
http://www.openwall.com/lists/oss-security/2021/06/10/14
https://www.jenkins.io/security/advisory/2021-06-10/#SECURITY-2367
Related Vulnerabilities
CVE-2021-3803 Vulnerability in npm package nth-check
CVE-2019-10746 Vulnerability in maven package org.webjars.npm:mixin-deep
CVE-2019-19899 Vulnerability in maven package io.pebbletemplates:pebble
CVE-2021-30246 Vulnerability in npm package jsrsasign
CVE-2020-2109 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-cps