Jenkins did not validate or otherwise limit the possible values administrators could specify as Jenkins root URL. This resulted in a cross-site scripting vulnerability exploitable by users with Overall/Administer permission. References: https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1471
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1764477]