CVE-2020-2170

Severity
5.4MEDIUM
EPSS
0.2%
top 53.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 24

Description

Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Stored XSS vulnerability in Jenkins RapidDeploy Plugin2022-05-24
GHSA
Stored XSS vulnerability in Jenkins RapidDeploy Plugin2022-05-24
CVEList
CVE-2020-2170: Jenkins RapidDeploy Plugin 42020-03-25

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-03-252020-03-25