PT-2020-15442 · Jenkins · Jenkins Matrix Authorization Strategy Plugin+1
Wadeck Follonier
·
Published
2020-07-15
·
Updated
2023-10-25
·
CVE-2020-2226
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Matrix Authorization Strategy Plugin versions 2.6.1 and earlier
Description
The issue is related to a stored cross-site scripting vulnerability. It occurs because user names shown in the configuration or permission table are not properly escaped. This can be exploited by a user with specific permissions, such as Job/Configure, Agent/Configure, or Overall/Administer, depending on the authorization setup. The vulnerability allows for the execution of malicious scripts.
Recommendations
For Jenkins Matrix Authorization Strategy Plugin versions 2.6.1 and earlier, update to version 2.6.2 or later, which escapes user names in the permission table, addressing the stored cross-site scripting vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Matrix Authorization Strategy Plugin