Description
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Link Directory PHP Object Injection (5.5.0)
WordPress Plugin WP Media Cleaner Multiple Cross-Site Scripting Vulnerabilities (2.2.6)
Jboss EAP Improper Input Validation Vulnerability (CVE-2018-1000873)
WordPress Plugin IMPress for IDX Broker Unspecified Vulnerability (2.5.11)
WordPress Plugin Google Maps v3 Shortcode Cross-Site Scripting (1.2.1)