Vulnerabilities > Jenkins > Jenkins > 2.204.2

DATE CVE VULNERABILITY TITLE RISK
2020-08-12 CVE-2020-2231 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
network
low complexity
jenkins CWE-79
5.4
2020-08-12 CVE-2020-2230 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
network
low complexity
jenkins CWE-79
5.4
2020-08-12 CVE-2020-2229 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2223 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2222 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2221 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2220 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-03-25 CVE-2020-2163 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
network
low complexity
jenkins CWE-79
5.4
2020-03-25 CVE-2020-2162 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-03-25 CVE-2020-2161 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
network
low complexity
jenkins CWE-79
5.4