Description
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
Product status
2.416 (maven) before *
2.401.3 (maven) before 2.401.*
2.414.1 (maven) before 2.414.*
References
www.jenkins.io/security/advisory/2023-07-26/ (Jenkins Security Advisory 2023-07-26)
www.openwall.com/lists/oss-security/2023/07/26/2