CVE-2020-2229
CVE-2020-2229
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Affected products
Jenkins project · Jenkinspublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/160443/Jenkins-2.235.3-Cross-Site-Scripting.htmlunverifiedexploitdbwww.exploit-db.com/exploits/49232unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →