Record summary

CVE-2020-2140 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListThrough 3.2affected

org.jenkins-ci.plugins:audit-trail

Browse Maven / org.jenkins-ci.plugins:audit-trail
GitHub AdvisoryBefore 3.3 · Fixed in 3.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMJenkin Audit Trail <=3.2 - Cross-Site ScriptingCVSS 6.1

Jenkins Audit Trail 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to potential data theft, session hijacking, or defacement.

Remediation

Upgrade to the latest version of Jenkin Audit Trail (>=3.3) which includes a fix for this vulnerability.

WeaknessesCWE-79
Authorsj3ssie/geraldino2
Template tagscvecve2020jenkinsxsspluginvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jenkins:audit_trail:*:*:*:*:*:jenkins:*:*

Source: ProjectDiscovery

References

5