Description
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
Remediation
References
Related Vulnerabilities
Python CVE-2019-17514 Vulnerability (CVE-2019-17514)
WordPress Plugin PowerPress Podcasting by Blubrry SQL Injection (6.0.2)
WordPress Plugin WP Easy Gallery 'select_gallery' Parameter Cross-Site Scripting (1.7)
Apache Tomcat version older than 5.5.26
WordPress Plugin Visual CSS Style Editor Security Bypass (7.1.9)