CVE-2020-2221: XSS
A flaw was found in Jenkins versions 2.244 and prior and in LTS 2.235.1 and prior. The upstream job's display name is not escaped on build time trend pages which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure permission for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job’s display name shown as part of a build cause. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2221?
The severity of CVE-2020-2221 is high with a severity value of 8.
How does CVE-2020-2221 affect Jenkins?
CVE-2020-2221 affects Jenkins versions 2.244 and prior and LTS 2.235.1 and prior.
What is the risk of CVE-2020-2221?
CVE-2020-2221 poses a risk of a stored cross-site scripting (XSS) vulnerability.
How can I fix CVE-2020-2221?
To fix CVE-2020-2221, upgrade to Jenkins version 2.245 or apply the appropriate security patch provided by Red Hat.
Where can I find more information about CVE-2020-2221?
You can find more information about CVE-2020-2221 in the Jenkins Security Advisory and the Red Hat Security Advisory linked in the references.