Description
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
Remediation
References
Related Vulnerabilities
Python Unchecked Return Value Vulnerability (CVE-2021-4189)
WordPress Plugin Contact Form by BestWebSoft Cross-Site Scripting (3.51)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)
WordPress Plugin eShop Code Injection (6.3.11)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease SQL Injection (4.1.4)