logo

CVE-2020-2111 org.jenkins-ci.plugins:subversion

Package

Manager: maven
Name: org.jenkins-ci.plugins:subversion
Vulnerable Version: >=0 <2.13.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00083 pctl0.25181

Details

Subversion Plugin stored XSS vulnerability Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability. Subversion Plugin 2.13.1 escapes the affected part of the error message.

Metadata

Created: 2022-05-24T17:08:46Z
Modified: 2023-12-06T14:31:03Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-x3pr-fcgm-wjgc
Finding: F425
Auto approve: 1