Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-2220

Опубликовано: 15 июл. 2020
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

A flaw was found in Jenkins versions 2.244 and prior and in LTS 2.235.1 and prior. The agent name is not escaped on build time trend pages which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure permission for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1857425jenkins: Stored XSS vulnerability in job build time trend

EPSS

Процентиль: 61%
0.00419
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
debian
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the ...

CVSS3: 8
github
больше 3 лет назад

Stored XSS vulnerability in Jenkins job build time trend

EPSS

Процентиль: 61%
0.00419
Низкий

8 High

CVSS3