CVE-2020-2248: XSS
Published Sep 1, 2020
·Updated
Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.
Affected Software
1 affected component
Jenkins Jsgames Jenkins<=0.2
Event History
Sep 1, 2020
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-2248?
CVE-2020-2248 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS).
2
How do I fix CVE-2020-2248?
To fix CVE-2020-2248, upgrade the JSGames Plugin to version 0.3 or later, as earlier versions are vulnerable to this XSS issue.
3
What software versions are vulnerable to CVE-2020-2248?
Jenkins JSGames Plugin versions 0.2 and earlier are vulnerable to CVE-2020-2248.
4
What is the impact of CVE-2020-2248?
The impact of CVE-2020-2248 allows an attacker to inject malicious code that could execute in the context of a user's browser.
5
How does CVE-2020-2248 occur?
CVE-2020-2248 occurs when the JSGames Plugin evaluates part of a URL as code, leading to a reflected cross-site scripting vulnerability.