PT-2020-2657 · Jenkins · Jenkins Queue Cleanup Plugin+1

Wadeck Follonier

·

Published

2020-03-25

·

Updated

2023-11-02

·

CVE-2020-2169

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Queue cleanup Plugin versions 1.3 and earlier
Description The issue is related to a form validation endpoint in the Jenkins Queue cleanup Plugin that does not properly escape a query parameter displayed in an error message, resulting in a reflected cross-site scripting (XSS) vulnerability. This vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks. The plugin's failure to protect its web page structure is a key factor in this vulnerability.
Recommendations For Jenkins Queue cleanup Plugin versions 1.3 and earlier, update to version 1.4 or later, which correctly escapes the query parameter and resolves the issue. As a temporary workaround, consider restricting access to the form validation endpoint until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2020-02701
CVE-2020-2169
GHSA-M7PR-M4CX-6M22

Affected Products

Jenkins
Jenkins Queue Cleanup Plugin