Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.3)
WordPress Plugin Login/Signup Popup (Inline Form + Woocommerce) Cross-Site Scripting (1.4)
WordPress Plugin Clipboard Images Arbitrary File Upload (0.3)
WordPress Plugin Subscribe to Comments Multiple Cross-Site Scripting Vulnerabilities (2.0.4)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2047)