CVE-2020-2136: XSS
Published Mar 9, 2020
·Updated
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:git<=4.2.0
4.2.1
jenkins Git Jenkins<=4.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.plugins:gitto a version that resolves this vulnerability.Fixed in 4.2.1
Event History
Mar 9, 2020
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
05:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-2136?
The severity of CVE-2020-2136 is medium with a CVSS score of 5.4.
2
What is the vulnerability description of CVE-2020-2136?
CVE-2020-2136 is a stored cross-site scripting vulnerability in Jenkins Git Plugin 4.2.0 and earlier due to the error message not being escaped for the repository URL for Microsoft TFS field form validation.
3
How can I mitigate CVE-2020-2136?
To mitigate CVE-2020-2136, update Jenkins Git Plugin to version 4.2.1 or later.