PT-2020-15487 · Jenkins · Jenkins Android Lint Plugin+1

Wadeck Follonier

·

Published

2020-09-16

·

Updated

2023-11-02

·

CVE-2020-2262

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Android Lint Plugin versions 2.6 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. It occurs because the plugin does not escape the annotation message in tooltips. This can be exploited by attackers who can provide report files to the plugin's post-build step.
Recommendations For Jenkins Android Lint Plugin versions 2.6 and earlier, update to a version later than 2.6 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-2262
GHSA-28X9-HC4P-9VH2

Affected Products

Jenkins
Jenkins Android Lint Plugin