Description
Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-1939
Related Vulnerabilities
CVE-2015-5347 Vulnerability in maven package org.apache.wicket:wicket-extensions
CVE-2023-38700 Vulnerability in npm package matrix-appservice-irc
CVE-2019-0231 Vulnerability in maven package org.apache.mina:mina-core
CVE-2016-6651 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2023-27096 Vulnerability in maven package cn.hippo4j:hippo4j-all