Description
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slideshow Gallery LITE Cross-Site Scripting (1.5.3.4)
WordPress Plugin YITH Desktop Notifications for WooCommerce Security Bypass (1.2.7)
phpBB CVE-2008-4125 Vulnerability (CVE-2008-4125)
WordPress Plugin Discount Rules for WooCommerce Security Bypass (2.2.0)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-44854)