PT-2020-15302 · Jenkins · Jenkins Gitlab Hook Plugin+1

J3Ssiejjj

·

Published

2020-01-15

·

Updated

2024-02-25

·

CVE-2020-2096

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Gitlab Hook Plugin versions 1.4.2 and earlier
Description The issue is related to a reflected XSS vulnerability. It occurs because project names in the "build now" endpoint are not properly escaped, allowing for potential exploitation.
Recommendations For Jenkins Gitlab Hook Plugin versions 1.4.2 and earlier, as a temporary workaround, consider disabling the build now endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2096
GHSA-8696-836P-C8QP

Affected Products

Jenkins
Jenkins Gitlab Hook Plugin