CVE-2020-2175
07.04.2020, 13:15
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin.
Vendor | Product | Version |
---|---|---|
jenkins | fitnesse | 𝑥 ≤ 1.31 |
𝑥
= Vulnerable software versions