Lucene search

K
redhatcveRedhat.comRH:CVE-2020-2162
HistoryAug 22, 2021 - 1:30 p.m.

CVE-2020-2162

2021-08-2213:30:39
redhat.com
access.redhat.com
36
jenkins
content-security-policy
file parameters
stored xss
vulnerability

EPSS

0.001

Percentile

22.0%

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.