SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Jenkins plugin Gitlab Hook XSS

Category: WEB-ATTACKS      

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2096


Relevant Information