Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-2162
Jenkins 2.227 and earlier LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build resulting in a stored XSS vulnerability.