PT-2020-15458 · Jenkins · Jenkins Git Parameter Plugin+1

Wadeck Follonier

·

Published

2020-09-01

·

Updated

2023-11-02

·

CVE-2020-2238

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Git Parameter Plugin versions 0.9.12 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. This occurs because the repository field on the 'Build with Parameters' page is not properly escaped, allowing attackers with Job/Configure permission to exploit this weakness.
Recommendations For Jenkins Git Parameter Plugin versions 0.9.12 and earlier, update to version 0.9.13 or later, which properly escapes the repository field on the 'Build with Parameters' page.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2238
GHSA-J7Q2-C6R4-X2JW

Affected Products

Jenkins
Jenkins Git Parameter Plugin