CVE-2020-2096
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 89%
from disclosure to weapon1 days
Published on NVDJan 15
1st PoC+1d
VulnCheck+1970d
exploitation probability
89%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.
Affected products
Jenkins project · Jenkins Gitlab Hook Pluginpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/47927unverifiedcve_referencepacketstormsecurity.com/files/155967/Jenkins-Gitlab-Hook-1.4.2-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.