Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Amelia-Events & Appointments Booking Calendar Cross-Site Scripting (1.0.46)
PHP Resource Management Errors Vulnerability (CVE-2015-4024)
MySQL CVE-2020-14540 Vulnerability (CVE-2020-14540)
WordPress Plugin WP Comment Remix SQL Injection and HTML Injection Vulnerabilities (1.4.3)
WordPress Plugin Form for WordPress-Zoho Forms Cross-Site Scripting (3.0)