CVE-2020-2163: XSS
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.228 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.204.6
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2163?
CVE-2020-2163 has a medium severity level due to its potential for stored XSS exploitation.
How do I fix CVE-2020-2163?
To fix CVE-2020-2163, upgrade Jenkins to version 2.228 or 2.204.6 or later.
What versions of Jenkins are affected by CVE-2020-2163?
Jenkins versions 2.227 and earlier, as well as LTS 2.204.5 and earlier, are affected by CVE-2020-2163.
What type of vulnerability is CVE-2020-2163?
CVE-2020-2163 is categorized as a stored XSS (Cross-Site Scripting) vulnerability.
Who can exploit CVE-2020-2163?
CVE-2020-2163 can be exploited by users who have control over the list view column headers.