Medium severity6.1NVD Advisory· Published Mar 25, 2020· Updated Jun 17, 2026
CVE-2020-2169
CVE-2020-2169
Description
A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, resulting in a reflected XSS vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:queue-cleanupMaven | < 1.4 | 1.4 |
Affected products
2- Range: unspecified
Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2020/03/25/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-m7pr-m4cx-6m22ghsaADVISORY
- jenkins.io/security/advisory/2020-03-25/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-2169ghsaADVISORY
- github.com/jenkinsci/queue-cleanup-plugin/commit/b3e562a427e704fc15dafe7664bd67aafcd4e03eghsaWEB
- github.com/jenkinsci/queue-cleanup-plugin/commit/e7dae99aa3a414004e953303c7c687d65348de11ghsaWEB
News mentions
1- Jenkins Security Advisory 2020-03-25Jenkins Security Advisories · Mar 25, 2020