Description
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-2002 Vulnerability (CVE-2021-2002)
Oracle JRE CVE-2019-2989 Vulnerability (CVE-2019-2989)
WordPress Plugin UK Cookie Consent Cross-Site Scripting (2.3.9)
OpenSSL Cryptographic Issues Vulnerability (CVE-2012-0884)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-1103)