CVE-2020-2195: XSS
Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips.
This results in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.
Compact Columns Plugin 1.12 applies the configured markup formatter to the job description shown in tooltips.
Other sources
Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2195?
CVE-2020-2195 is considered a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2020-2195?
To fix CVE-2020-2195, update the Compact Columns Plugin to version 1.12 or later.
Who is affected by CVE-2020-2195?
Users with Job/Configure permission in Jenkins are affected by CVE-2020-2195.
What type of vulnerability is CVE-2020-2195?
CVE-2020-2195 is a stored cross-site scripting (XSS) vulnerability.
What products are impacted by CVE-2020-2195?
CVE-2020-2195 impacts the Compact Columns Plugin versions prior to 1.12 in Jenkins.