CVEs Blog | G5 Cyber Security

CVE-2020-2289 – Jenkins Active Choices Plugin 2.4 and earlier does not escape the name an

Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2289

Reference (s):

Exit mobile version