Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability.
id: CVE-2020-2096
info:
name: Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting
author: madrob
...