Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Remediation
References
Related Vulnerabilities
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)
MediaWiki Resource Management Errors Vulnerability (CVE-2015-2937)
WordPress Plugin GigPress 'Notes' Field HTML Injection (2.1.10)
WordPress Plugin Car Rental System Cross-Site Scripting (1.3)
WordPress Plugin Twitter Cards Meta Multiple Vulnerabilities (2.4.5)