CVE-2020-2244
published 2020-09-01CVE-2020-2244: Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS)…
medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | build_failure_analyzer | <= 1.27.0 | — |
| jenkins | build_failure_analyzer_plugin | — | — |
| jenkins | cadence_vmanager_plugin | — | — |
| jenkins | database_plugin | — | — |
| jenkins | git_parameter_plugin | — | — |
| jenkins | jsgames_plugin | — | — |
| jenkins | klocwork_analysis_plugin | — | — |
| jenkins | klocwork_plugin | — | — |
| jenkins | parameterized_remote_trigger_plugin | — | — |
| jenkins | readyapi_functional_testing_plugin | — | — |
| jenkins | valgrind_plugin | — | — |
| jenkins_project | jenkins_build_failure_analyzer_plugin | unspecified – 1.27.0 | — |