Vulnerability record · CVE-2020-2230 · published 12 August 2020
CVE-2020-2230: Jenkins stored XSS in project naming strategy description
Jenkins · Jenkins
Jenkins 2.251 and earlier, and LTS 2.235.3 and earlier, does not escape the project naming strategy description, allowing stored cross-site scripting. Because the payload persists in configuration and renders to other users, it can affect administrators and other users who view the affected page.
Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw requires an authenticated user with Overall/Manage permission and victim interaction, and CVSS rates it medium, though public exploit information and a high EPSS score raise concern.
What it is
Jenkins 2.251 and earlier, and LTS 2.235.3 and earlier, does not escape the project naming strategy description, allowing stored cross-site scripting. Because the payload persists in configuration and renders to other users, it can affect administrators and other users who view the affected page.
Impact
An attacker with Overall/Manage permission can store script that executes in the browser of any user viewing the naming strategy description, enabling session theft or actions in that user's context. The scope change in the CVSS vector reflects that the injected script can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through the Jenkins web UI by a user holding Overall/Manage permission; the victim must view the crafted description, so user interaction is required. No unauthenticated access is needed, but the attacker must already have that permission.
Exploitation
Not listed in CISA KEV. EPSS is high (0.82733, 99.651st percentile), and references include an Exploit-tagged third-party advisory, indicating public exploit information exists.
What to do
- Upgrade Jenkins to a version after 2.251 or LTS after 2.235.3 that includes the fix for SECURITY-1957.
- Restrict Overall/Manage permission to the smallest possible set of trusted accounts.
- Review and sanitize existing project naming strategy descriptions for injected script.
- Apply output encoding or a Content Security Policy to limit script execution in the Jenkins UI where feasible.
Detection
- Search Jenkins configuration and logs for project naming strategy descriptions containing script tags or event handler attributes.
- Monitor for unexpected changes to naming strategy configuration by non-administrative accounts.
- Alert on Jenkins audit log entries showing Overall/Manage permission grants or use by unusual accounts.
- Inspect web access logs for requests to naming strategy pages followed by anomalous client-side behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160443/Jenkins-2.235.3-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2020/08/12/4 | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1957 | Vendor Advisory |
| http://packetstormsecurity.com/files/160443/Jenkins-2.235.3-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2020/08/12/4 | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1957 | Vendor Advisory |
Track CVE-2020-2230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-2230), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.