jenkins: Stored XSS vulnerability in job build time trend
Published Jul 15, 2020
8.0
HIGHCVSS 3.1
EPSS 1.02%
Description
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=2.244
- Version unspecifiedStatusaffectedConstraints<=LTS 2.235.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins | n/a |
|
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.235.2.1597220898-1.el7
Fixed · RHSA-2020:3541
Red Hat OpenShift Container Platform 4.3
jenkins-0:2.235.5.1600415514-1.el7
Fixed · RHSA-2020:3808
Red Hat OpenShift Container Platform 4.4
jenkins-0:2.235.2.1597312065-1.el7
Fixed · RHBA-2020:3441
Red Hat OpenShift Container Platform 4.4
openshift-0:4.4.0-202008250319.p0.git.0.d653415.el7
Fixed · RHSA-2020:3579
Red Hat OpenShift Container Platform 4.5
jenkins-0:2.235.2.1597312414-1.el7
Fixed · RHSA-2020:3519
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.235.2.1597220898-1.el7 | Fixed | RHSA-2020:3541 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-0:2.235.5.1600415514-1.el7 | Fixed | RHSA-2020:3808 |
| Red Hat OpenShift Container Platform 4.4 | jenkins-0:2.235.2.1597312065-1.el7 | Fixed | RHBA-2020:3441 |
| Red Hat OpenShift Container Platform 4.4 | openshift-0:4.4.0-202008250319.p0.git.0.d653415.el7 | Fixed | RHSA-2020:3579 |
| Red Hat OpenShift Container Platform 4.5 | jenkins-0:2.235.2.1597312414-1.el7 | Fixed | RHSA-2020:3519 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2020/07/15/5 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-2220 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1857425 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4968 Advisory
- https://github.com/advisories/GHSA-qgj4-rc8m-44mq Advisory
- https://github.com/jenkinsci/jenkins/commit/b43531acee280dedc3ea454a2fc5a1a42990ddda
- https://jenkins.io/security/advisory/2020-07-15/#SECURITY-1868 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-2220
- https://www.cve.org/CVERecord?id=CVE-2020-2220
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2020/07/15/5 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-2220 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1857425 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4968 | Advisory | |
| https://github.com/advisories/GHSA-qgj4-rc8m-44mq | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/b43531acee280dedc3ea454a2fc5a1a42990ddda | ||
| https://jenkins.io/security/advisory/2020-07-15/#SECURITY-1868 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-2220 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-2220 |
Change history (0)
No recorded changes yet.