Description
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-1870
Related Vulnerabilities
CVE-2012-0394 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-html-support
CVE-2012-0047 Vulnerability in maven package org.apache.wicket:wicket
CVE-2020-6831 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-24785 Vulnerability in maven package org.webjars.bower:moment