CVE-2020-2199Cross-site Scripting in Project Jenkins Subversion Partial Release Manager Plugin

Severity
6.1MEDIUMNVD
EPSS
21.8%
top 4.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 24

Description

Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

🔴Vulnerability Details

3
OSV
XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin2022-05-24
GHSA
XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin2022-05-24
CVEList
CVE-2020-2199: Jenkins Subversion Partial Release Manager Plugin 12020-06-03

💥Exploits & PoCs

1
Exploit-DB
File Transfer iFamily 2.1 - Directory Traversal2020-04-15

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-06-032020-06-03
CVE-2020-2199 — Cross-site Scripting | cvebase