PT-2020-15512 · Jenkins · Jenkins Liquibase Runner Plugin+1
Daniel Beck
·
Published
2020-09-23
·
Updated
2023-11-02
·
CVE-2020-2283
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Liquibase Runner Plugin versions 1.4.5 and earlier
Description
The issue results in a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin does not escape changeset contents when showing them on the build page. Attackers who can provide Liquibase changesets evaluated by the plugin can exploit this vulnerability.
Recommendations
For versions 1.4.5 and earlier, consider disabling the evaluation of changesets by the plugin until a fix is available. Restrict access to the build page to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Liquibase Runner Plugin