PT-2020-15484 · Jenkins · Jenkins Computer-Queue-Plugin+1

Wadeck Follonier

·

Published

2020-09-16

·

Updated

2023-11-02

·

CVE-2020-2259

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins computer-queue-plugin Plugin versions 1.5 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability, which can be exploited by attackers with Agent/Configure permission. This occurs because the agent name in tooltips is not properly escaped.
Recommendations For Jenkins computer-queue-plugin Plugin versions 1.5 and earlier, update to version 1.6 or later, which properly escapes the agent name in tooltips, to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2259
GHSA-QG66-XV7V-M834

Affected Products

Jenkins
Jenkins Computer-Queue-Plugin