MEDIUM
Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations
Published Jan 29, 2020
5.4
MEDIUMCVSS 3.1
EPSS 0.73%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.