ZeroHour

CVE-2020-2173

CVSS 3.1
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.

Vendors
jenkins
Products
gatling
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.