Stored Cross-Site Scripting in Jenkins Coverage/Complexity Scatter Plot Plugin
CVE-2020-2265
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2020
What is CVE-2020-2265?
The Coverage/Complexity Scatter Plot Plugin prior to version 1.1.2 fails to properly escape method information in tooltips. This oversight can lead to a stored cross-site scripting (XSS) vulnerability, which can be exploited by attackers who manage to provide manipulated report files to the post-build step of the Jenkins plugin, potentially allowing for unauthorized actions or data exposure.
Affected Version(s)
Jenkins Coverage/Complexity Scatter Plot Plugin <= 1.1.1