CVE-2020-2194 Details
Description
Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability.
A stored cross-site scripting vulnerability has been identified in the Jenkins ECharts API Plugin, affecting versions 4.7.0-3 and earlier. The vulnerability arises because the plugin does not properly escape the display names of builds in the trend chart. This issue can be exploited by users with Run/Update permission.
Users of the Jenkins ECharts API Plugin should update to version 4.7.0-4, which addresses this vulnerability by properly escaping the display names before rendering.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1842 | CVE | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2020/06/03/3 | CVE | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1842 | [email protected] | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2020/06/03/3 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jenkins echarts api | <= 4.7.0-3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 25, 2023 | CVE Modified | [email protected] |
| Jun 3, 2020 | Initial Analysis | [email protected] |
| Jun 3, 2020 | CVE Modified | [email protected] |