PT-2020-15441 · Jenkins · Jenkins Matrix Project Plugin+1

Wadeck Follonier

·

Published

2020-07-15

·

Updated

2023-10-25

·

CVE-2020-2225

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Matrix Project Plugin versions 1.16 and earlier
Description The issue is related to a stored cross-site scripting vulnerability. It occurs because the axis names shown in tooltips on the overview page of builds with multiple axes are not properly escaped. This vulnerability is exploitable by users with Job/Configure permission.
Recommendations For Jenkins Matrix Project Plugin versions 1.16 and earlier, update to version 1.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the overview page of builds with multiple axes to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2225
GHSA-W43X-5F8F-686P
RHSA-2020:3453
RHSA-2020:3541
RHSA-2020:3625
RHSA-2020:4265

Affected Products

Jenkins
Jenkins Matrix Project Plugin