5.4
CVSSv3

CVE-2020-2223

Published: 15/07/2020 Updated: 25/10/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Jenkins 2.244 and previous versions, LTS 2.235.1 and previous versions does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

Vendor Advisories

Synopsis Important: OpenShift Container Platform 311 security update Type/Severity Security Advisory: Important Topic An update for jenkins, jenkins-2-plugins, openshift-ansible, and python-rsa is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as ...
Synopsis Important: OpenShift Container Platform 457 jenkins and openshift packages security update Type/Severity Security Advisory: Important Topic An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 45Red Hat Product Security has rated this update as having a ...
Synopsis Important: OpenShift Container Platform 4338 jenkins and openshift security update Type/Severity Security Advisory: Important Topic An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 43Red Hat Product Security has rated this update as having a security ...