CVE-2020-2113: XSS
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.tools:git-parameterto a version that resolves this vulnerability.Fixed in 0.9.12
Event History
Frequently Asked Questions
What is the vulnerability ID for this Jenkins Git Parameter Plugin vulnerability?
The vulnerability ID for this Jenkins Git Parameter Plugin vulnerability is CVE-2020-2113.
What is the severity of CVE-2020-2113?
The severity of CVE-2020-2113 is medium with a CVSS score of 5.4.
What is the description of CVE-2020-2113?
CVE-2020-2113 is a stored cross-site scripting vulnerability in Jenkins Git Parameter Plugin 0.9.11 and earlier, which allows users with Job/Configure permission to exploit it.
How does CVE-2020-2113 impact Jenkins Git Parameter Plugin?
CVE-2020-2113 allows users with Job/Configure permission to exploit a stored cross-site scripting vulnerability in Jenkins Git Parameter Plugin 0.9.11 and earlier.
Is there a fix available for CVE-2020-2113?
Yes, please refer to the official Jenkins security advisory for instructions on fixing CVE-2020-2113.