Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-2222

Опубликовано: 15 июл. 2020
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

A flaw was found in jenkins in versions prior to 2.244 and versions prior to LTS 2.235.1. Job names in the 'Keep this build forever' badge tooltip are not properly escaped which results in a stored cross-site scripting (XSS) vulnerability exploitable by users able to configure job names. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1857431jenkins: Stored XSS vulnerability in 'keep forever' badge icons

EPSS

Процентиль: 66%
0.00519
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
debian
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the ...

CVSS3: 8
github
больше 3 лет назад

Stored XSS vulnerability in Jenkins 'keep forever' badge icon

EPSS

Процентиль: 66%
0.00519
Низкий

8 High

CVSS3