Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Stars Menu Cross-Site Scripting (1.0.1)
Plone CMS Improper Privilege Management Vulnerability (CVE-2020-7938)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3436)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5012)