Cross-site scripting vulnerability in Jenkins through HTML content - CVE-2020-2223 (dpkg)ID: oval:org.secpod.oval:def:65168 | Date: (C)2020-08-17 (M)2023-11-02 |
Class: VULNERABILITY | Family: unix |
The host is installed with Jenkins LTS through 2.235.1 or Jenkins rolling release through 2.244 and is prone to a cross-site scripting vulnerability. A flaw is present in the application, which fails to properly handle escaping 'href' attribute of links to downstream jobs displayed in the build console page. Successful exploitation could allow attackers to cause a stored XSS vulnerability.
Product: |
Jenkins LTS |
Jenkins rolling release |