Description
Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-2892
Related Vulnerabilities
CVE-2011-1772 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2023-34434 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2018-16115 Vulnerability in maven package com.typesafe.akka:akka-actor_2.11
CVE-2023-24440 Vulnerability in maven package org.jenkins-ci.plugins:jira-steps