PT-2020-15302 · Jenkins · Jenkins Gitlab Hook Plugin+1
J3Ssiejjj
·
Published
2020-01-15
·
Updated
2024-02-25
·
CVE-2020-2096
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Gitlab Hook Plugin versions 1.4.2 and earlier
Description
The issue is related to a reflected XSS vulnerability. It occurs because project names in the "build now" endpoint are not properly escaped, allowing for potential exploitation.
Recommendations
For Jenkins Gitlab Hook Plugin versions 1.4.2 and earlier, as a temporary workaround, consider disabling the
build now endpoint until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Gitlab Hook Plugin