jenkins: user-specified tooltip values leads to stored cross-site scripting
Published Aug 12, 2020
5.4
MEDIUMCVSS 3.1
EPSS 6.77%
Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=2.251
- Version unspecifiedStatusaffectedConstraints<=LTS 2.235.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins | n/a |
|
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.235.5.1600415953-1.el7
Fixed · RHSA-2020:4223
Red Hat OpenShift Container Platform 4.3
jenkins-0:2.235.5.1600415514-1.el7
Fixed · RHSA-2020:3808
Red Hat OpenShift Container Platform 4.4
openshift4/ose-jenkins:v4.4.0-202009260441.p0
Fixed · RHSA-2020:4220
Red Hat OpenShift Container Platform 4.5
jenkins-0:2.235.5.1600414805-1.el7
Fixed · RHSA-2020:3841
Red Hat Fuse 7
jenkins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.235.5.1600415953-1.el7 | Fixed | RHSA-2020:4223 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-0:2.235.5.1600415514-1.el7 | Fixed | RHSA-2020:3808 |
| Red Hat OpenShift Container Platform 4.4 | openshift4/ose-jenkins:v4.4.0-202009260441.p0 | Fixed | RHSA-2020:4220 |
| Red Hat OpenShift Container Platform 4.5 | jenkins-0:2.235.5.1600414805-1.el7 | Fixed | RHSA-2020:3841 |
| Red Hat Fuse 7 | jenkins | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://packetstormsecurity.com/files/160443/Jenkins-2.235.3-Cross-Site-Scripting.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2020/08/12/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-2229 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1874830 Issue Tracking
- https://github.com/advisories/GHSA-hvmc-7g2x-r3p9 Advisory
- https://github.com/jenkinsci/jenkins/commit/fe4cbe03804d6240d0b58d0b2301ea9530a34916
- https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1955 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-2229
- https://www.cve.org/CVERecord?id=CVE-2020-2229
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/160443/Jenkins-2.235.3-Cross-Site-Scripting.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://www.openwall.com/lists/oss-security/2020/08/12/4 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-2229 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1874830 | Issue Tracking | |
| https://github.com/advisories/GHSA-hvmc-7g2x-r3p9 | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/fe4cbe03804d6240d0b58d0b2301ea9530a34916 | ||
| https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1955 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-2229 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-2229 |
Change history (0)
No recorded changes yet.