CVE-2020-2225
published 2020-07-15CVE-2020-2225: Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in…
PriorityP422medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.04%
60.2th percentile
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | deployer_framework_plugin | — | — |
| jenkins | gitlab_authentication_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | matrix_project | <= 1.16 | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins_project | jenkins_matrix_project_plugin | unspecified – 1.16 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
osv·2022-05-24
CVE-2020-2225 [HIGH] Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.
Matrix Project Plugin 1.17 escapes the axis names shown in these tooltips.
GHSA
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
ghsa·2022-05-24
CVE-2020-2225 [HIGH] CWE-79 Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.
Matrix Project Plugin 1.17 escapes the axis names shown in these tooltips.
Jenkins
Jenkins Security Advisory 2020-07-15
vendor_jenkins·2020-07-15·CVSS 5.4
CVE-2020-2220 [MEDIUM] Jenkins Security Advisory 2020-07-15
Title: Jenkins Security Advisory 2020-07-15
Jenkins Security Advisory 2020-07-15
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Deployer Framework
Plugin
GitLab Authentication
Plugin
Matrix Authorization Strategy
Plugin
Matrix Project
Plugin
Descriptions
Stored XSS vulnerability in jo
Red Hat
jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips
vendor_redhat·2020-07-15·CVSS 5.4
CVE-2020-2225 [MEDIUM] CWE-79 jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips
jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.
A flaw was found in the Matrix Project Plugin version 1.16 and prior. Node names shown in tooltips are not escaped on the overview page of builds with multiple axes which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure permission for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2225 jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips
bugzilla·2020-07-15·CVSS 5.4
CVE-2020-2225 [MEDIUM] CVE-2020-2225 jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips
CVE-2020-2225 jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips
Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.
References:
https://www.jenkins.io/security/advisory/2020-07-15/
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3453 https://access.redhat.com/errata/RHSA-2020:3453
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-2225
---
This issue has been
arXiv
eyeballvul: a future-proof benchmark for vulnerability detection in the wild
arxiv_fulltext·2024-07-13
eyeballvul: a future-proof benchmark for vulnerability detection in the wild
*-0.5cm
center
[email protected]
center
## Abstract
Long contexts of recent LLMs have enabled a new use case: asking models to find security vulnerabilities in entire codebases. To evaluate model performance on this task, we introduce eyeballvul: a benchmark designed to test the vulnerability detection capabilities of language models at scale, that is sourced and updated weekly from the stream of published vulnerabilities in open-source repositories. The benchmark consists of a list of revisions in different repositories, each associated with the list of known vulnerabilities present at that revision. An LLM-based scorer is used to compare the list of possible vulnerabilities returned by a model to the list of known vulnerabilities for each revision. As of July 2024, eyeballvu
2020-07-15
Published