Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Svennergr

#21893of 53,624
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-15319
5.4
2020-02-12
Jenkins · Jenkins Git Parameter Plugin · CVE-2020-2112
**Name of the Vulnerable Software and Affected Versions** Jenkins Git Parameter Plugin versions 0.9.11 and earlier **Description** The issue results in a stored cross-site scripting vulnerability. It is exploitable by users with Job/Configure permission due to the parameter name not being escaped on the UI. **Recommendations** For Jenkins Git Parameter Plugin versions 0.9.11 and earlier, update to a version that fixes the stored cross-site scripting vulnerability.
PT-2020-15320
5.4
2020-02-12
Jenkins · Jenkins Git Parameter Plugin · CVE-2020-2113
**Name of the Vulnerable Software and Affected Versions** Jenkins Git Parameter Plugin versions 0.9.11 and earlier **Description** The issue results in a stored cross-site scripting vulnerability. This is exploitable by users with Job/Configure permission. The vulnerability occurs because the default value shown on the UI is not escaped. **Recommendations** For Jenkins Git Parameter Plugin versions 0.9.11 and earlier, update to a version that fixes this issue to prevent exploitation.