Fedora Account System
Red Hat Associate
Red Hat Customer
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. Reference: https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017