CVEs Blog | G5 Cyber Security

CVE-2020-2266 – Jenkins Description Column Plugin 1.3 and earlier does not escape the job

Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2266

Reference (s):

Exit mobile version