Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4412 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token. |
Github GHSA |
GHSA-jpvq-v729-7j2h | Improper Neutralization of Input During Web Page Generation in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T07:01:41.196Z
Reserved: 2019-12-05T00:00:00.000Z
Link: CVE-2020-2231
No data.
Status : Modified
Published: 2020-08-12T14:15:13.267
Modified: 2024-11-21T05:25:01.700
Link: CVE-2020-2231
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA