Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000392
- https://jenkins.io/security/advisory/2017-11-08/
- http://www.securityfocus.com/bid/101773
- http://www.securityfocus.com/bid/102826
- https://github.com/jenkinsci/jenkins/commit/f67068170b55633571e5462e52b6124b23d7cb84
- https://github.com/advisories/GHSA-5ppx-rgw2-xg23