PT-2020-15437 · Cloudbees+1 · Jenkins

Wadeck Follonier

·

Published

2020-07-15

·

Updated

2024-03-06

·

CVE-2020-2221

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.244 and earlier Jenkins LTS versions 2.235.1 and earlier
Description The issue results from the failure to escape the upstream job's display name shown as part of a build cause, leading to a stored cross-site scripting issue.
Recommendations For Jenkins versions 2.244 and earlier, update to version 2.245 or later. For Jenkins LTS versions 2.235.1 and earlier, update to version 2.235.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2020-2221
CVE-2020-2221
GHSA-G4J6-M3M3-CRW8
RHSA-2020:3519
RHSA-2020:3541
RHSA-2020:3808

Affected Products

Jenkins