Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-0154)
MySQL CVE-2019-2455 Vulnerability (CVE-2019-2455)
Joomla! Core 1.0.x SQL Injection (1.0.0 - 1.0.11)
Oracle JRE Incorrect Conversion between Numeric Types Vulnerability (CVE-2022-34169)
Oracle Database Server Improper Authentication Vulnerability (CVE-2012-3137)