Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Symposium Open Redirect (13.04)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3412)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6105)
Oracle JRE CVE-2013-2394 Vulnerability (CVE-2013-2394)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9547)