Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-22116 Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-04T07:01:40.978Z

Reserved: 2019-12-05T00:00:00

Link: CVE-2020-2161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-25T17:15:15.000

Modified: 2024-11-21T05:24:49.760

Link: CVE-2020-2161

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-25T00:00:00Z

Links: CVE-2020-2161 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses