Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
Remediation
References
Related Vulnerabilities
Drupal Incorrect Authorization Vulnerability (CVE-2022-25274)
WordPress Plugin Easy Modal Multiple SQL Injection Vulnerabilities (2.0.17)
Dolibarr Improper Input Validation Vulnerability (CVE-2022-0174)
Django Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0483)
Sqlite Integer Overflow or Wraparound Vulnerability (CVE-2018-20346)