cbcvebase.
CVE-2020-2136
published 2020-03-09

CVE-2020-2136: Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsaudit_trail_plugin
jenkinsbacklog_plugin
jenkinscobertura_plugin
jenkinscredentials_plugin
jenkinscryptomove_plugin
jenkinsdeployhub_plugin
jenkinsgit<= 4.2.0
jenkinsgit_plugin
jenkinsliterate_plugin
jenkinslogstash_plugin
jenkinsmac_cloud_host_launched_by_the_plugin
jenkinsmac_plugin
jenkinsopenshift_deployer_plugin
jenkinsp4_plugin
jenkinsquality_gates_plugin
jenkinsrepository_connector_plugin
jenkinsrundeck_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security_plugin
jenkinsskytap_cloud_ci_plugin
jenkinssonar_quality_gates_plugin
jenkinssubversion_release_manager_plugin
jenkinstimestamper_plugin
jenkinsyaml_input_files_to_literate_plugin
jenkinszephyr_enterprise_test_management_plugin