CVE-2020-2264: XSS
Published Sep 16, 2020
·Updated
Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Affected Software
1 affected component
jenkins Custom Job Icon Jenkins<=0.2
Event History
Sep 16, 2020
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-2264?
CVE-2020-2264 is classified as a medium severity vulnerability related to stored cross-site scripting (XSS) in Jenkins.
2
How do I fix CVE-2020-2264?
To fix CVE-2020-2264, upgrade the Jenkins Custom Job Icon Plugin to version 0.3 or later.
3
What versions are affected by CVE-2020-2264?
CVE-2020-2264 affects Jenkins Custom Job Icon Plugin versions 0.2 and earlier.
4
What type of vulnerability is CVE-2020-2264?
CVE-2020-2264 is a stored cross-site scripting (XSS) vulnerability.
5
Who can exploit the CVE-2020-2264 vulnerability?
The CVE-2020-2264 vulnerability can be exploited by attackers with Job/Configure permissions.