{"id":"CVE-2020-2217","details":"Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.","aliases":["GHSA-rfrq-3v89-fqg6"],"modified":"2026-08-19T15:12:29.494905Z","published":"2020-07-02T15:15:18.600Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/07/02/7"},{"type":"ADVISORY","url":"https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1771"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eficode/compatibility-action-storage-plugin","events":[{"introduced":"0"},{"last_affected":"0b32641e0c0d7b89ff7e07fc99ef7bde5f654be5"}],"database_specific":{"cpe":"cpe:2.3:a:praqma:compatibility_action_storage:*:*:*:*:*:jenkins:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0"}],"source":"CPE_RANGE"}}],"versions":["compatibility-action-storage-1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-2217.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}