Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability.
View the template here CVE-2020-2096.yaml
References:
https://github.com/Elsfa7-110/kenzer-templates