First published: Wed Jan 15 2020(Updated: )
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Gitlab Hook | <=1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2096 is classified as a medium severity vulnerability due to its reflected cross-site scripting (XSS) nature.
To fix CVE-2020-2096, upgrade the Jenkins Gitlab Hook Plugin to version 1.4.3 or later.
CVE-2020-2096 affects Jenkins Gitlab Hook Plugin versions 1.4.2 and earlier.
CVE-2020-2096 is a reflected cross-site scripting (XSS) vulnerability.
There are no known workarounds for CVE-2020-2096; updating to the latest version is recommended.