Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Remediation
References
Related Vulnerabilities
WordPress Plugin Migration, Backup, Staging-WPvivid Directory Traversal (0.9.75)
Oracle JRE CVE-2022-21618 Vulnerability (CVE-2022-21618)
MediaWiki Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2020-25827)
phpMyFAQ Weak Password Requirements Vulnerability (CVE-2023-0793)