PT-2020-15451 · Jenkins · Jenkins

Pierre Beitz

·

Published

2020-08-12

·

Updated

2024-03-06

·

CVE-2020-2230

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.251 and earlier Jenkins LTS versions 2.235.3 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability. This occurs because the project naming strategy description is not properly escaped, allowing users with Overall/Manage permission to exploit it. The vulnerability is exploitable when the description is displayed on item creation.
Recommendations For Jenkins versions 2.251 and earlier, update to version 2.252 or later to resolve the issue. For Jenkins LTS versions 2.235.3 and earlier, update to version 2.235.4 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2020-2230
CVE-2020-2230
GHSA-9G4M-FFX6-C29G
RHSA-2020:3808
RHSA-2020:3841
RHSA-2020:4223

Affected Products

Jenkins