Description
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-3162 Vulnerability (CVE-2018-3162)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8669)
WordPress Plugin Author Chat Unspecified Vulnerability (1.9.0)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7852)
Apache HTTP Server Double Free Vulnerability (CVE-2026-23918)