CVE-2020-2244
01.09.2020, 14:15
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
Vendor | Product | Version |
---|---|---|
jenkins | build_failure_analyzer | 𝑥 ≤ 1.27.0 |
𝑥
= Vulnerable software versions