Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-2231

Опубликовано: 12 авг. 2020
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

A flaw was found in Jenkins versions prior to 2.251 and LTS 2.235.3. The remote address of hosts starting a build via 'Trigger builds remotely' are not properly escaped leading to a potential stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the authentication token. The highest threat from this vulnerability is to data confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsFixedRHSA-2020:422322.10.2020
Red Hat OpenShift Container Platform 4.3jenkinsFixedRHSA-2020:380823.09.2020
Red Hat OpenShift Container Platform 4.4openshift4/ose-jenkinsFixedRHSA-2020:422013.10.2020
Red Hat OpenShift Container Platform 4.5jenkinsFixedRHSA-2020:384130.09.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1875234jenkins: stored XSS vulnerability in 'trigger builds remotely'

EPSS

Процентиль: 64%
0.00472
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

CVSS3: 5.4
debian
больше 5 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the ...

CVSS3: 5.4
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Jenkins

EPSS

Процентиль: 64%
0.00472
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2020-2231