Description
Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2768
Related Vulnerabilities
CVE-2014-0075 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-42128 Vulnerability in maven package com.liferay:com.liferay.headless.delivery.impl
CVE-2022-34813 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2023-46233 Vulnerability in npm package crypto-js
CVE-2023-49673 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner