Record summary

CVE-2020-2096 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListThrough 1.4.2affected
next of 1.4.2unknown

org.jenkins-ci.ruby-plugins:gitlab-hook

Browse Maven / org.jenkins-ci.ruby-plugins:gitlab-hook
GitHub AdvisoryThrough 1.4.2affected

Proofs of concept

1

Catalogued exploits

ExploitDBJenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site ScriptingExploitDB exploitby Ai HoNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMJenkins Gitlab Hook <=1.4.2 - Cross-Site ScriptingCVSS 6.1

Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.

Remediation

Upgrade to the latest version of Jenkins Gitlab Hook plugin (>=1.4.3) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsmadrobot
Template tagscve2020cvejenkinsxssgitlabpluginpacketstormvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jenkins:gitlab_hook:*:*:*:*:*:jenkins:*:*
Shodan: http.title:"GitLab"
Shodan: http.title:"gitlab"
FOFA: title="gitlab"
Google: intitle:"gitlab"

Source: ProjectDiscovery

References

5