CVE-2020-3841
published 2020-02-27CVE-2020-3841: The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.55%
42.6th percentile
The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.3.1 and iPadOS 13.3.1 | iOS 13.3.1 and iPadOS 13.3.1 |
| apple | ipados | < 13.3.1 | 13.3.1 |
| apple | iphone_os | < 13.3.1 | 13.3.1 |
| apple | safari | < 13.0.5 | 13.0.5 |
| apple | safari | >= unspecified < Safari 13.0.5 | Safari 13.0.5 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2230 jenkins: stored XSS vulnerability in project naming strategy
bugzilla·2020-09-03·CVSS 5.4
CVE-2020-2230 [MEDIUM] CVE-2020-2230 jenkins: stored XSS vulnerability in project naming strategy
CVE-2020-2230 jenkins: stored XSS vulnerability in project naming strategy
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description that is displayed on item creation. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
Discussion:
External References:
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1957
---
Created jenkins tracking bugs for this issue:
Affects: fedora-31 [bug 1875233]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3841 https://access.redhat.com/errata/RHSA-2020:3841
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(
Bugzilla
CVE-2020-2231 jenkins: stored XSS vulnerability in 'trigger builds remotely'
bugzilla·2020-09-03·CVSS 5.4
CVE-2020-2231 [MEDIUM] CVE-2020-2231 jenkins: stored XSS vulnerability in 'trigger builds remotely'
CVE-2020-2231 jenkins: stored XSS vulnerability in 'trigger builds remotely'
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely'. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Discussion:
External References:
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1960
---
Created jenkins tracking bugs for this issue:
Affects: fedora-31 [bug 1875235]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3841 https://access.redhat.com/errata/RHSA-2020:3841
---
This bug is now closed. Further updates for individua
Bugzilla
CVE-2020-2229 jenkins: user-specified tooltip values leads to stored cross-site scripting
bugzilla·2020-09-02·CVSS 5.4
CVE-2020-2229 [MEDIUM] CVE-2020-2229 jenkins: user-specified tooltip values leads to stored cross-site scripting
CVE-2020-2229 jenkins: user-specified tooltip values leads to stored cross-site scripting
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons. Tooltip values can be contributed by plugins, some of which use user-specified values. This results in a stored cross-site scripting (XSS) vulnerability.
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-31 [bug 1874831]
---
External References:
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1955
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3841 https://access.redhat.com/errata/RHSA-2020:3841
---
This bug is now closed. Further updates for individual products will be reflected on the
2020-02-27
Published