Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-0652 Vulnerability (CVE-2016-0652)
Piwigo Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-26267)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4390)
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2016-7137)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3837)