CVE-2020-2223: Jenkins
Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
Affected products
- Jenkins Jenkins: up to and including 2.235.1; up to and including 2.244
Published 2020-07-15. Last modified 2026-06-17.