Vulnerability Details CVE-2020-2246
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report contents.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2020-2246
-
cpe:2.3:a:jenkins:valgrind:-
-
cpe:2.3:a:jenkins:valgrind:0.1
-
cpe:2.3:a:jenkins:valgrind:0.10
-
cpe:2.3:a:jenkins:valgrind:0.11
-
cpe:2.3:a:jenkins:valgrind:0.12
-
cpe:2.3:a:jenkins:valgrind:0.13
-
cpe:2.3:a:jenkins:valgrind:0.14
-
cpe:2.3:a:jenkins:valgrind:0.15
-
cpe:2.3:a:jenkins:valgrind:0.16
-
cpe:2.3:a:jenkins:valgrind:0.17
-
cpe:2.3:a:jenkins:valgrind:0.18
-
cpe:2.3:a:jenkins:valgrind:0.19
-
cpe:2.3:a:jenkins:valgrind:0.2
-
cpe:2.3:a:jenkins:valgrind:0.20
-
cpe:2.3:a:jenkins:valgrind:0.21
-
cpe:2.3:a:jenkins:valgrind:0.22
-
cpe:2.3:a:jenkins:valgrind:0.23
-
cpe:2.3:a:jenkins:valgrind:0.24
-
cpe:2.3:a:jenkins:valgrind:0.25
-
cpe:2.3:a:jenkins:valgrind:0.26
-
cpe:2.3:a:jenkins:valgrind:0.27
-
cpe:2.3:a:jenkins:valgrind:0.28
-
cpe:2.3:a:jenkins:valgrind:0.3
-
cpe:2.3:a:jenkins:valgrind:0.4
-
cpe:2.3:a:jenkins:valgrind:0.5
-
cpe:2.3:a:jenkins:valgrind:0.6
-
cpe:2.3:a:jenkins:valgrind:0.7
-
cpe:2.3:a:jenkins:valgrind:0.8
-
cpe:2.3:a:jenkins:valgrind:0.9