PT-2020-15512 · Jenkins · Jenkins Liquibase Runner Plugin+1

Daniel Beck

·

Published

2020-09-23

·

Updated

2023-11-02

·

CVE-2020-2283

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Liquibase Runner Plugin versions 1.4.5 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin does not escape changeset contents when showing them on the build page. Attackers who can provide Liquibase changesets evaluated by the plugin can exploit this vulnerability.
Recommendations For versions 1.4.5 and earlier, consider disabling the evaluation of changesets by the plugin until a fix is available. Restrict access to the build page to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2283
GHSA-9HG7-XMF8-JXF9

Affected Products

Jenkins
Jenkins Liquibase Runner Plugin