CVE-2020-2111 – org.jenkins-ci.plugins:subversion
Package
Manager: maven
Name: org.jenkins-ci.plugins:subversion
Vulnerable Version: >=0 <2.13.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00083 pctl0.25181
Details
Subversion Plugin stored XSS vulnerability Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability. Subversion Plugin 2.13.1 escapes the affected part of the error message.
Metadata
Created: 2022-05-24T17:08:46Z
Modified: 2023-12-06T14:31:03Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-x3pr-fcgm-wjgc
Finding: F425
Auto approve: 1