A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
https://github.com/advisories/GHSA-hv45-5j9h-7fhg
https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1129