Reflected XSS Vulnerability in Gitlab Hook Plugin for Jenkins
CVE-2020-2096
What is CVE-2020-2096?
The Jenkins Gitlab Hook Plugin prior to version 1.4.2 contains a reflected Cross-Site Scripting (XSS) vulnerability due to inadequate escaping of project names in the build_now endpoint. An attacker could exploit this flaw to inject and execute arbitrary scripts in the context of the user's session, compromising web application security and allowing for potential data exfiltration or unauthorized operations. It is crucial for administrators to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Gitlab Hook Plugin <= 1.4.2
References
EPSS Score
93% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved