Stored Cross-Site Scripting Vulnerability in Jenkins Static Analysis Utilities Plugin
CVE-2020-2316
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 4 November 2020
What is CVE-2020-2316?
The Jenkins Static Analysis Utilities Plugin, in versions 1.96 and earlier, is susceptible to a stored cross-site scripting flaw due to improper escaping of annotation messages in tooltips. This vulnerability allows attackers with Job/Configure permissions to inject malicious scripts, potentially compromising the security of the Jenkins environment by executing unauthorized actions or stealing sensitive information.
Affected Version(s)
Jenkins Static Analysis Utilities Plugin <= 1.96