CVE-2020-2265

Cross-site Scripting in maven/io.jenkins.plugins/covcomplplot

Identifiers

CVE-2020-2265

Package Slug

maven/io.jenkins.plugins/covcomplplot

Vulnerability

Cross-site Scripting

Description

Jenkins Coverage/Complexity Scatter Plot Plugin does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.

Affected Versions

All versions up to 1.1.1

Solution

Unfortunately, there is no solution available yet.

Last Modified

2020-09-21

source