VYPR

Brakeman Plugin

by Jenkins Project

CVEs (1)

  • CVE-2020-2122MedFeb 12, 2020
    risk 0.35cvss 5.4epss 0.01

    Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.