CVE Database
/

CVE-2020-2173

Back to search

CVE-2020-2173

Published: Apr 7, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.

VendorProductVersions

Jenkins project

Jenkins Gatling Plugin

affected
unspecified - <= 1.2.7
affected
1.2.2 - < unspecified

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now