CVE-2020-2230
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
MEDIUM · CVSS 5.4
EPSS 0.01279
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0