Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 Maven

Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin

GHSA-6c7r-6p5m-cp82 · CVE-2020-2136

Published · Modified

Description

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes