Description
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.
Remediation
References
Related Vulnerabilities
WordPress Plugin Content Cards Cross-Site Scripting (0.9.6)
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1581)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-13402)
Varnish Cache Reachable Assertion Vulnerability (CVE-2019-15892)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1251)