CVE-2020-2230
Jenkins 2.235.3 - 'Description' Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
Jenkins versiones 2.251 y anteriores, versiones LTS 2.235.3 y anteriores, no escapan la descripciĆ³n de la estrategia de nombramiento del proyecto, resultando en una vulnerabilidad de tipo cross-site scripting (XSS) almacenado explotable por usuarios con permiso General y de AdministraciĆ³n
A flaw was found in Jenkins in versions prior to 2.251 and LTS 2.235.3. The project naming strategy description, displayed on item creation, is not properly escaped. This can result in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permissions. The highest threat from this vulnerability is to data confidentiality and integrity.
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Issues addressed include cross site scripting and information leakage vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-05 CVE Reserved
- 2020-08-12 CVE Published
- 2020-12-11 First Exploit
- 2024-08-04 CVE Updated
- 2025-01-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2020/08/12/4 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/160443 | 2020-12-11 | |
https://www.exploit-db.com/exploits/49237 | 2020-12-11 | |
http://packetstormsecurity.com/files/160443/Jenkins-2.235.3-Cross-Site-Scripting.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1957 | 2023-11-02 | |
https://access.redhat.com/security/cve/CVE-2020-2230 | 2020-10-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1875232 | 2020-10-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jenkins Search vendor "Jenkins" | Jenkins Search vendor "Jenkins" for product "Jenkins" | <= 2.235.3 Search vendor "Jenkins" for product "Jenkins" and version " <= 2.235.3" | lts |
Affected
| ||||||
Jenkins Search vendor "Jenkins" | Jenkins Search vendor "Jenkins" for product "Jenkins" | <= 2.251 Search vendor "Jenkins" for product "Jenkins" and version " <= 2.251" | - |
Affected
|