Description
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin 10WebAnalytics Cross-Site Request Forgery (1.2.8)
WordPress Plugin Permalink Manager Lite Cross-Site Request Forgery (2.2.19.2)
Apache Traffic Server Remote DOS Attack (CVE-2021-27737)
Nginx Out-of-bounds Write Vulnerability (CVE-2022-41741)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2717)