.. / CVE-2020-2140

Exploit for Jenkin Audit Trail <=3.2 - Cross-Site Scripting (CVE-2020-2140)

Description:

Jenkins Audit Trail 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

Nuclei Template

View the template here CVE-2020-2140.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-2140.yaml
Copy

References:

https://www.jenkins.io/security/advisory/2020-03-09/
https://nvd.nist.gov/vuln/detail/CVE-2020-2140
https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1722
http://www.openwall.com/lists/oss-security/2020/03/09/1
https://github.com/merlinepedra25/nuclei-templates