PT-2020-15442 · Jenkins · Jenkins Matrix Authorization Strategy Plugin+1

Wadeck Follonier

·

Published

2020-07-15

·

Updated

2023-10-25

·

CVE-2020-2226

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Matrix Authorization Strategy Plugin versions 2.6.1 and earlier
Description The issue is related to a stored cross-site scripting vulnerability. It occurs because user names shown in the configuration or permission table are not properly escaped. This can be exploited by a user with specific permissions, such as Job/Configure, Agent/Configure, or Overall/Administer, depending on the authorization setup. The vulnerability allows for the execution of malicious scripts.
Recommendations For Jenkins Matrix Authorization Strategy Plugin versions 2.6.1 and earlier, update to version 2.6.2 or later, which escapes user names in the permission table, addressing the stored cross-site scripting vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2226
GHSA-VR6V-WJFW-RXCR
RHSA-2020:3453
RHSA-2020:3541
RHSA-2020:3625
RHSA-2020:4265

Affected Products

Jenkins
Jenkins Matrix Authorization Strategy Plugin