CVEs Blog | G5 Cyber Security

CVE-2020-2256 – Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not esca

Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job’s display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2256

Reference (s):

Exit mobile version