PT-2020-15415 · Jenkins · Jenkins Sonargraph Integration Plugin+1

·

CVE-2020-2201

·

Published

2020-07-02

·

Updated

2023-10-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Sonargraph Integration Plugin versions 3.0.0 and earlier
Description The issue results in a stored cross-site scripting vulnerability due to the failure to escape the file path for the Log file field form validation. This can be exploited by users with Job/Configure permission, allowing for potential malicious activities.
Recommendations For Jenkins Sonargraph Integration Plugin versions 3.0.0 and earlier, update to version 3.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Log file field form validation to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2201
GHSA-F799-HFG3-48JP

Affected Products

Jenkins
Jenkins Sonargraph Integration Plugin