VulnerabilityModified
CVE-2020-2225
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.
MEDIUM 5.4EPSS 1.04%
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jenkins/matrix project
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2020/07/15/5Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2020-07-15/#SECURITY-1925Vendor Advisory
- http://www.openwall.com/lists/oss-security/2020/07/15/5Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2020-07-15/#SECURITY-1925Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.