Vulnerabilities > Jenkins > Gatling > 1.2.5

DATE CVE VULNERABILITY TITLE RISK
2020-04-07 CVE-2020-2173 Cross-site Scripting vulnerability in Jenkins Gatling
Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.
network
low complexity
jenkins CWE-79
5.4