jenkins: Multiple vulnerabilities (CVE-2020-2229, CVE-2020-2230, CVE-2020-2231)ID: oval:org.secpod.oval:def:1801802 | Date: (C)2021-01-27 (M)2023-11-10 |
Class: PATCH | Family: unix |
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons. Tooltip values can be contributed by plugins, some of which use user-specified values.Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description that is displayed on item creation.Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via "Trigger builds remotely".
Platform: |
Alpine Linux 3.13 |