CVE-2020-2217
02.07.2020, 15:15
Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Vendor | Product | Version |
---|---|---|
praqma | compatibility_action_storage | 𝑥 ≤ 1.0 |
𝑥
= Vulnerable software versions