Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
Liferay DXP Excessive Iteration Vulnerability (CVE-2024-25144)
WordPress Plugin Insert Pages Cross-Site Scripting (3.7.4)
Oracle Application Server Other Vulnerability (CVE-2005-1496)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5629)
WordPress Plugin Slideshow Gallery LITE Multiple Cross-Site Scripting Vulnerabilities (1.6.5)