PT-2020-15458 · Jenkins · Jenkins Git Parameter Plugin+1

·

CVE-2020-2238

·

Published

2020-09-01

·

Updated

2023-11-02

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Git Parameter Plugin versions 0.9.12 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. This occurs because the repository field on the 'Build with Parameters' page is not properly escaped, allowing attackers with Job/Configure permission to exploit this weakness.
Recommendations For Jenkins Git Parameter Plugin versions 0.9.12 and earlier, update to version 0.9.13 or later, which properly escapes the repository field on the 'Build with Parameters' page.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2238
GHSA-J7Q2-C6R4-X2JW

Affected Products

Jenkins
Jenkins Git Parameter Plugin