CVE-2020-2225

MEDIUM

Jenkins Matrix Project Plugin <1.16 - XSS

Title source: llm
STIX 2.1

Description

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/07/15/5

Scores

CVSS v3 5.4
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
jenkins/matrix_project < 1.16
org.jenkins-ci.plugins/matrix-project 0 - 1.17Maven
Published Jul 15, 2020
Tracked Since Feb 18, 2026