Cross-Site Scripting Vulnerability in Jenkins Build Failure Analyzer Plugin by Jenkins
CVE-2020-2244
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 1 September 2020
What is CVE-2020-2244?
The Jenkins Build Failure Analyzer Plugin versions up to 1.27.0 are susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of form validation responses. This lack of necessary escaping techniques allows attackers to inject malicious scripts into the console output of builds. When these scripts are executed by users, it could compromise the security of the Jenkins server and its users, making the affected versions highly exposed to such attacks. It is crucial for Jenkins administrators to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Jenkins Build Failure Analyzer Plugin <= 1.27.0