CVEs Blog | G5 Cyber Security

CVE-2020-2221 – Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the up

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job’s display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2221

Reference (s):

Exit mobile version