Since Jenkins 2.340, symbol-based icons unescape previously escaped values of tooltip
parameters.
This vulnerability is known to be exploitable by attackers with Job/Configure permission.
Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability. Symbol-based icons no longer unescape values of tooltip
parameters.
{ "nvd_published_at": "2022-06-23T17:15:00Z", "github_reviewed_at": "2022-12-06T00:02:19Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-22", "CWE-79" ] }