CVE-2020-2136: Jenkins Git
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
Affected products
- Jenkins Git: up to and including 4.2.0
Published 2020-03-09. Last modified 2026-06-17.