Reflected Cross-Site Scripting in Jenkins Subversion Plugin by CloudBees
CVE-2020-2199
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 3 June 2020
What is CVE-2020-2199?
The Jenkins Subversion Partial Release Manager Plugin, up to version 1.0.1, has a security flaw that allows an attacker to execute a reflected cross-site scripting (XSS) attack. This vulnerability occurs because the plugin does not properly escape error messages in the repository URL field during form validation, enabling malicious scripts to be injected and executed in the context of the user's browser. This could potentially lead to unauthorized interactions with the Jenkins server, jeopardizing the integrity of sensitive data and user sessions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Subversion Partial Release Manager Plugin <= 1.0.1
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved