CVE-2020-2243: XSS
Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2243?
CVE-2020-2243 has a medium severity level due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2020-2243?
To fix CVE-2020-2243, upgrade the Jenkins Cadence vManager Plugin to version 3.0.5 or later.
Who is affected by CVE-2020-2243?
CVE-2020-2243 affects users of Jenkins Cadence vManager Plugin versions 3.0.4 and earlier with Run/Update permissions.
What are the potential impacts of CVE-2020-2243?
The potential impacts of CVE-2020-2243 include execution of arbitrary JavaScript in the context of the user’s session.
Is CVE-2020-2243 easy to exploit?
CVE-2020-2243 can be easily exploited by attackers who have sufficient permissions to modify build descriptions.