Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Permalinks Cross-Site Scripting (0.1.19)
Apache HTTP Server Other Vulnerability (CVE-2021-33193)
WordPress Plugin WordPress Automatic Security Bypass (3.53.2)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2042)
WordPress Plugin oQey Gallery 'gal_id' Parameter SQL Injection (0.4.8)