Description
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.
Remediation
References
https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3140
Related Vulnerabilities
CVE-2017-4994 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2014-8115 Vulnerability in maven package org.kie:kie-drools-wb-distribution-wars
CVE-2020-4076 Vulnerability in maven package org.webjars.npm:electron
CVE-2017-12647 Vulnerability in maven package com.liferay:com.liferay.knowledge.base.service
CVE-2023-33006 Vulnerability in maven package org.jenkins-ci.plugins:wso2id-oauth