Severity
5.4MEDIUM
EPSS
0.1%
top 69.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateAug 19

Description

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin2022-05-24
GHSA
Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin2022-05-24
CVEList
CVE-2020-2190: Jenkins Script Security Plugin 12020-06-03

📋Vendor Advisories

4
Red Hat
podman: Security regression of CVE-2020-14370 due to source code management issue2022-08-19
Red Hat
podman: Security regression of CVE-2020-8945 due to source code management issue2022-08-19
Jenkins
Jenkins Security Advisory 2020-06-032020-06-03
Red Hat
jenkins-script-security-plugin: cross-site scripting vulnerability due to configure sandboxed scripts2020-06-03

💬Community

1
Bugzilla
CVE-2020-2190 jenkins-script-security-plugin: cross-site scripting vulnerability due to configure sandboxed scripts2020-06-16
CVE-2020-2190 (MEDIUM CVSS 5.4) | Jenkins Script Security Plugin 1.72 | cvebase.io