CVE-2020-2161: XSS
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.228 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.204.6 - Upgrade
Upgrade
Jenkins LTSto a version that resolves this vulnerability.Fixed in 2.204.6
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2161?
CVE-2020-2161 is classified as a medium severity stored XSS vulnerability.
How do I fix CVE-2020-2161?
To fix CVE-2020-2161, upgrade Jenkins to version 2.228 or later or LTS version 2.204.6 or later.
Who is affected by CVE-2020-2161?
CVE-2020-2161 affects Jenkins versions 2.227 and earlier, as well as LTS versions 2.204.5 and earlier.
What type of vulnerability is CVE-2020-2161?
CVE-2020-2161 is a stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2020-2161 be exploited remotely?
Yes, CVE-2020-2161 can be exploited remotely by users who have permission to define node labels.