Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Remediation
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop 'ajax_save_name.php' Remote Code Execution (2.2.3)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (3.2.21)
Drupal Improper Input Validation Vulnerability (CVE-2015-3234)
WordPress Plugin RSVPmaker Excel Cross-Site Scripting (1.1)
WordPress Plugin Ultimate Membership Pro SQL Injection (3.3)