CVE-2020-2265
maven/io.jenkins.plugins/covcomplplot
Cross-site Scripting
Jenkins Coverage/Complexity Scatter Plot Plugin does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
All versions up to 1.1.1
Unfortunately, there is no solution available yet.
2020-09-21
source |