PT-2020-15318 · Jenkins · Jenkins Subversion Plugin +1

Wadeck Follonier

·

Published

2020-02-12

·

Updated

2023-10-25

·

CVE-2020-2111

CVSS v3.1
5.4
VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Jenkins Subversion Plugin versions 2.13.0 and earlier

Description:

The issue is related to a stored cross-site scripting vulnerability. It occurs because the error message for the Project Repository Base URL field form validation is not properly escaped. This allows for potential malicious script injection. The Subversion Plugin 2.13.1 escapes the affected part of the error message, indicating a fix.

Recommendations:

For Jenkins Subversion Plugin versions 2.13.0 and earlier, update to version 2.13.1 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2111
GHSA-X3PR-FCGM-WJGC
RHSA-2020:2478
RHSA-2020:2737
RHSA-2020:3616

Affected Products

Jenkins
Jenkins Subversion Plugin