CVEs Blog | G5 Cyber Security

CVE-2020-2112 – Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the param

Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2112

Reference (s):

Exit mobile version