Description
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2567
Related Vulnerabilities
CVE-2022-44730 Vulnerability in maven package org.apache.xmlgraphics:batik-script
CVE-2023-27603 Vulnerability in maven package org.apache.linkis:linkis-common
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2023-37478 Vulnerability in npm package @pnpm/macos-x64
CVE-2022-34202 Vulnerability in maven package com.geteasyqa:easyqa