Vulnerability record · CVE-2020-2096 · published 15 January 2020
CVE-2020-2096: Jenkins Gitlab Hook Plugin reflected XSS in build_now endpoint
Jenkins · Gitlab Hook
The Jenkins Gitlab Hook Plugin (1.4.2 and earlier) fails to escape project names in the build_now endpoint, producing a reflected cross-site scripting flaw. An attacker who can get a victim to load a crafted URL can run script in the victim's Jenkins session context.
Description
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityReflected XSS requires user interaction and has limited direct impact, but the very high EPSS score and public exploit raise the practical risk.
What it is
The Jenkins Gitlab Hook Plugin (1.4.2 and earlier) fails to escape project names in the build_now endpoint, producing a reflected cross-site scripting flaw. An attacker who can get a victim to load a crafted URL can run script in the victim's Jenkins session context.
Impact
An attacker can execute arbitrary JavaScript in a victim's browser session, potentially stealing session cookies or performing actions as the authenticated Jenkins user.
Attack surface
Reached over the network via a crafted URL to the build_now endpoint; no authentication is required by the attacker, but the victim must click or be directed to the link (UI:R per the CVSS vector).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.9279, 99.8th percentile) and public exploit references exist (Packet Storm), indicating active interest and available proof-of-concept code.
What to do
- Upgrade the Jenkins Gitlab Hook Plugin to a version later than 1.4.2 that escapes project names.
- If upgrade is not immediately possible, restrict access to the Jenkins instance and the build_now endpoint to trusted networks.
- Apply output encoding to project names in any custom or interim fix.
- Review Jenkins plugin inventory for other outdated plugins and patch them in the same maintenance window.
Detection
- Search web/proxy logs for requests to the build_now endpoint containing script-like or encoded payloads in parameters.
- Monitor for anomalous JavaScript or HTML tags in Jenkins request parameters and referrers.
- Alert on Jenkins plugin versions matching Gitlab Hook 1.4.2 or earlier in asset inventories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155967/Jenkins-Gitlab-Hook-1.4.2-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2020/01/15/1 | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2020-01-15/#SECURITY-1683 | Vendor Advisory |
| http://packetstormsecurity.com/files/155967/Jenkins-Gitlab-Hook-1.4.2-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2020/01/15/1 | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2020-01-15/#SECURITY-1683 | Vendor Advisory |
Track CVE-2020-2096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-2096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.