First published: Mon Mar 09 2020(Updated: )
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Git | <=4.2.0 | |
maven/org.jenkins-ci.plugins:git | <=4.2.0 | 4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-2136 is medium with a CVSS score of 5.4.
CVE-2020-2136 is a stored cross-site scripting vulnerability in Jenkins Git Plugin 4.2.0 and earlier due to the error message not being escaped for the repository URL for Microsoft TFS field form validation.
To mitigate CVE-2020-2136, update Jenkins Git Plugin to version 4.2.1 or later.