PT-2020-15433 · Jenkins · Jenkins Compatibility Action Storage Plugin

Wadeck Follonier

·

Published

2020-07-02

·

Updated

2023-11-02

·

CVE-2020-2217

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Compatibility Action Storage Plugin versions 1.0 and earlier
Description The issue is related to a reflected cross-site scripting (XSS) vulnerability. It occurs because the plugin does not escape the content coming from the MongoDB in the "testConnection form validation endpoint", which is an API endpoint. This allows for potential XSS attacks.
Recommendations For Jenkins Compatibility Action Storage Plugin versions 1.0 and earlier, consider disabling the testConnection form validation endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2217
GHSA-RFRQ-3V89-FQG6

Affected Products

Jenkins Compatibility Action Storage Plugin