← Vulnerability feed

Vulnerability record · CVE-2020-2230 · published 12 August 2020

CVE-2020-2230: Jenkins stored XSS in project naming strategy description

Jenkins · Jenkins

Jenkins 2.251 and earlier, and LTS 2.235.3 and earlier, does not escape the project naming strategy description, allowing stored cross-site scripting. Because the payload persists in configuration and renders to other users, it can affect administrators and other users who view the affected page.

5.4 CVSS 3.1 Medium EPSS 83% · top 0.3% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw requires an authenticated user with Overall/Manage permission and victim interaction, and CVSS rates it medium, though public exploit information and a high EPSS score raise concern.

What it is

Jenkins 2.251 and earlier, and LTS 2.235.3 and earlier, does not escape the project naming strategy description, allowing stored cross-site scripting. Because the payload persists in configuration and renders to other users, it can affect administrators and other users who view the affected page.

Impact

An attacker with Overall/Manage permission can store script that executes in the browser of any user viewing the naming strategy description, enabling session theft or actions in that user's context. The scope change in the CVSS vector reflects that the injected script can affect resources beyond the vulnerable component.

Attack surface

Reached over the network through the Jenkins web UI by a user holding Overall/Manage permission; the victim must view the crafted description, so user interaction is required. No unauthenticated access is needed, but the attacker must already have that permission.

Exploitation

Not listed in CISA KEV. EPSS is high (0.82733, 99.651st percentile), and references include an Exploit-tagged third-party advisory, indicating public exploit information exists.

What to do

  • Upgrade Jenkins to a version after 2.251 or LTS after 2.235.3 that includes the fix for SECURITY-1957.
  • Restrict Overall/Manage permission to the smallest possible set of trusted accounts.
  • Review and sanitize existing project naming strategy descriptions for injected script.
  • Apply output encoding or a Content Security Policy to limit script execution in the Jenkins UI where feasible.

Detection

  • Search Jenkins configuration and logs for project naming strategy descriptions containing script tags or event handler attributes.
  • Monitor for unexpected changes to naming strategy configuration by non-administrative accounts.
  • Alert on Jenkins audit log entries showing Overall/Manage permission grants or use by unusual accounts.
  • Inspect web access logs for requests to naming strategy pages followed by anomalous client-side behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23897Jenkins CLI parser arbitrary file read via @ path expansionJenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a fi…KEVEPSS 100%analysed9.8CVE-2018-1000861Jenkins Stapler framework URL routing allows remote code executionThe Stapler web framework in Jenkins 2.153 and earlier and LTS 2.138.3 and earlier lets attackers invoke unintended Java methods by requesting crafte…KEVEPSS 98%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2015-5317Jenkins Fingerprints pages expose job and build namesJenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. T…KEVEPSS 23%analysed9.8CVE-2021-21690Jenkins path traversal vulnerabilityAgent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, …EPSS 2.5%9.8CVE-2021-21691Jenkins link following vulnerabilityCreating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and…EPSS 2.1%9.8CVE-2021-21692Jenkins path traversal vulnerabilityFilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access p…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2020-2230), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.