Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.
https://github.com/jenkinsci/jenkins/commit/fd2e081b947124c90bcd97bfc55e1a7f2ef41a74
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2601
http://www.securityfocus.com/bid/95960
http://www.openwall.com/lists/oss-security/2022/06/30/3
http://www.openwall.com/lists/oss-security/2022/06/22/3
https://github.com/advisories/GHSA-vf5v-6wjm-vr7v
https://github.com/advisories/GHSA-hqmp-vxj7-5wpq
https://github.com/advisories/GHSA-88r9-hfj2-54hv
https://github.com/advisories/GHSA-x95w-qf3m-pqpx
https://github.com/advisories/GHSA-pv38-mqpp-v72h
https://github.com/advisories/GHSA-pc9c-547w-hhmc
https://github.com/advisories/GHSA-jhfv-8936-g652
https://github.com/advisories/GHSA-hc44-p2qq-cfm9
https://github.com/advisories/GHSA-gpw4-7mcw-m8vx
https://github.com/advisories/GHSA-fcqr-gh8w-wm8f
https://github.com/advisories/GHSA-cqhr-q835-62gm
https://github.com/advisories/GHSA-7558-6q45-6x7m
https://github.com/advisories/GHSA-6923-546p-6rrc
https://github.com/advisories/GHSA-6882-385p-hhhw
https://github.com/advisories/GHSA-65r6-w7vr-c75r
https://github.com/advisories/GHSA-5hh2-f4h9-446g
https://github.com/advisories/GHSA-5247-whvj-83qw
https://github.com/advisories/GHSA-438w-rjj9-5fjf
https://github.com/advisories/GHSA-ppwv-mvqg-q89h
https://github.com/advisories/GHSA-mw4r-5mfc-m5vc
https://github.com/advisories/GHSA-h3v9-46pp-h33w
https://github.com/advisories/GHSA-9w23-w757-mvv8
https://github.com/advisories/GHSA-7rjv-q3pp-wc4p
https://github.com/advisories/GHSA-7j66-wvhr-m83x
https://github.com/advisories/GHSA-5pmp-7wc9-v7vw
https://github.com/advisories/GHSA-r69c-5j7c-vm6q
https://github.com/advisories/GHSA-455j-8hg5-8576
https://github.com/advisories/GHSA-wpr6-qvcq-8269
https://github.com/advisories/GHSA-pjm3-f4vh-3h3h
https://github.com/advisories/GHSA-m3p3-2gp6-ghq8
https://github.com/advisories/GHSA-f3jq-9c79-j65m
https://github.com/advisories/GHSA-v98r-gjgc-m9pf
https://github.com/advisories/GHSA-pv7p-c7cp-vrh3