{"id":"GHSA-6xxf-rwv4-mrjm","summary":"Stored XSS vulnerability in Jenkins Timestamper Plugin","details":"Timestamper Plugin 1.11.1 and earlier does not escape or sanitize the HTML formatting used to display the timestamps in console output for builds.\n\nThis results in a stored cross-site scripting vulnerability that can be exploited by users with Overall/Administer permission.\n\nTimestamper Plugin 1.11.2 sanitizes the HTML formatting for timestamps and only allows basic, safe HTML formatting.","aliases":["CVE-2020-2137"],"modified":"2024-01-02T05:49:44.072501Z","published":"2022-05-24T17:10:27Z","database_specific":{"nvd_published_at":"2020-03-09T16:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-05T20:18:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-2137"},{"type":"WEB","url":"https://github.com/jenkinsci/timestamper-plugin/commit/6637c3e599c330e03251005675beeadb46d8495b"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/timestamper-plugin"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1784"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2020/03/09/1"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:timestamper","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/timestamper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.2"}]}],"versions":["1.10","1.11","1.11.1","1.3","1.3.1","1.3.2","1.4","1.5","1.5.1","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.16","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6","1.6.2","1.7","1.7.1","1.7.2","1.7.3","1.7.4","1.8.1","1.8.10","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","1.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.11.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6xxf-rwv4-mrjm/GHSA-6xxf-rwv4-mrjm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}