vendor:
Jenkins
by:
gx1
5.4
CVSS
MEDIUM
Stored Cross-Site Scripting
79
CWE
Product Name: Jenkins
Affected Version From: <= 2.251 and <= LTS 2.235.3
Affected Version To: 2.252 and LTS 2.235.4
Patch Exists: YES
Related CWE: CVE-2020-2229
CPE: a:jenkins:jenkins
Other Scripts:
N/A
Platforms Tested: any
2020
Jenkins 2.235.3 – ‘tooltip’ Stored Cross-Site Scripting
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons. Tooltip values can be contributed by plugins, some of which use user-specified values. This results in a stored cross-site scripting (XSS) vulnerability. Jenkins 2.252, LTS 2.235.4 escapes the tooltip content of help icons.
Mitigation:
Upgrade to Jenkins 2.252, LTS 2.235.4 or later.