CVEs Blog | G5 Cyber Security

CVE-2020-2136 – Jenkins Git Plugin 4.2.0 and earlier does not escape the error message fo

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2136

Reference (s):

Exit mobile version