CVEs Blog | G5 Cyber Security

CVE-2020-2264 – Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job de

Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2264

Reference (s):

Exit mobile version