Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
Python Improper Input Validation Vulnerability (CVE-2021-29921)
Joomla Incorrect Authorization Vulnerability (CVE-2021-26027)
XOOPS Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-0613)
Squid Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2021-28652)
WordPress Plugin Bug Library Unspecified Vulnerability (2.0.7)