CVE-2020-2113 is a vulnerability in Jenkins Git Parameter
Published on February 12, 2020
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
Products Associated with CVE-2020-2113
Want to know whenever a new CVE is published for Jenkins Git Parameter? stack.watch will email you.
Affected Versions
Jenkins project Jenkins Git Parameter Plugin:- Version 0.9.4 and below unspecified is affected.
- Version unspecified, <= 0.9.11 is affected.
Exploit Probability
EPSS
0.12%
Percentile
31.13%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.