Lucene search

K
osvGoogleOSV:CVE-2020-2231
HistoryAug 12, 2020 - 2:15 p.m.

CVE-2020-2231

2020-08-1214:15:13
Google
osv.dev
5

AI Score

5.4

Confidence

High

EPSS

0.007

Percentile

80.6%

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via ‘Trigger builds remotely’, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

AI Score

5.4

Confidence

High

EPSS

0.007

Percentile

80.6%