Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-2224

Опубликовано: 15 июл. 2020
Источник: redhat
CVSS3: 8

Описание

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

A flaw was found in the Matrix Project Plugin version 1.16 and prior. Node names shown in tooltips are not escaped on the overview page of builds with a single axis which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure permission for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1857436jenkins-2-plugins/matrix-project: Stored XSS vulnerability in single axis builds tooltips

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
github
больше 3 лет назад

Stored XSS vulnerability in single axis builds tooltips in Jenkins Matrix Project Plugin

8 High

CVSS3

Уязвимость CVE-2020-2224