CVE-2020-2223

MEDIUM

Jenkins < 2.235.1, < 2.244 - Stored Cross-Site Scripting in Build Console Page

Title source: llm
STIX 2.1

Description

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/07/15/5

Scores

CVSS v3 5.4
EPSS 0.0051
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
jenkins/jenkins < 2.235.1
jenkins/jenkins < 2.244
org.jenkins-ci.main/jenkins-core 0 - 2.235.2Maven
Published Jul 15, 2020
Tracked Since Feb 18, 2026