CVE-2020-2173

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/04/2020
Last modified:
02/11/2023

Description

Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:gatling:*:*:*:*:*:jenkins:*:* 1.2.7 (including)