Jenkins did not validate or otherwise limit the possible values administrators could specify as Jenkins root URL. This resulted in a cross-site scripting vulnerability exploitable by users with Overall/Administer permission.
References:
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1471