Launch Week Day 1: Announcing Security Design Review
HIGH 8.0 Maven

Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin

GHSA-vr6v-wjfw-rxcr · CVE-2020-2226

Published · Modified

Description

Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the permission table. This results in a stored cross-site scripting (XSS) vulnerability. When using project-based matrix authorization, this vulnerability can be exploited by a user with Job/Configure or Agent/Configure permission, otherwise by users with Overall/Administer permission.

Matrix Authorization Strategy Plugin 2.6.2 escapes user names in the permission table.

Ready to move

Start Securing

Free, no credit card | First findings in minutes