Description
Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Thrive Leads Security Bypass (2.3.9.3)
Oracle Database Server CVE-2010-0911 Vulnerability (CVE-2010-0911)
Oracle JRE CVE-2014-0453 Vulnerability (CVE-2014-0453)
WordPress Plugin CM Pop-Up banners for WordPress SQL Injection (1.5.10)
WordPress Plugin Hero Maps Premium Cross-Site Scripting (2.2.1)