cbcvebase.
CVE-2020-2229
published 2020-08-12

CVE-2020-2229: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS)…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EXPLOIT
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinsemail_extension_plugin
jenkinsflaky_test_handler_plugin
jenkinsids_in_pipeline_maven_integration_plugin
jenkinsjenkins<= 2.235.3
jenkinsjenkins<= 2.251
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinspipeline_maven_integration_plugin
jenkinsyet_another_build_visualizer_plugin
jenkins_projectjenkinsunspecified – 2.251