CVE-2020-2220: XSS
A flaw was found in Jenkins versions 2.244 and prior and in LTS 2.235.1 and prior. The agent name is not escaped on build time trend pages which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure permission for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name on build time trend pages. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Agent/Configure permission.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-2220.
What is the severity of CVE-2020-2220?
The severity of CVE-2020-2220 is high.
How does CVE-2020-2220 occur?
CVE-2020-2220 occurs when the agent name is not properly escaped on build time trend pages in Jenkins.
What is the impact of CVE-2020-2220?
CVE-2020-2220 can lead to a stored cross-site scripting (XSS) vulnerability.
How can CVE-2020-2220 be fixed?
To fix CVE-2020-2220, update Jenkins to version 2.245 or later.