CVEs Blog | G5 Cyber Security

CVE-2020-2220 – Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the ag

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2220

Reference (s):

Exit mobile version