Medium severity5.4NVD Advisory· Published Aug 12, 2020· Updated Jun 17, 2026
CVE-2020-2236
CVE-2020-2236
Description
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.axis.system.jenkins.plugins.downstream:yet-another-build-visualizerMaven | < 1.12 | 1.12 |
Affected products
3cpe:2.3:a:jenkins:yet_another_build_visualizer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jenkins:yet_another_build_visualizer:*:*:*:*:*:*:*:*range: <=1.11
- (no CPE)range: unspecified
- ghsa-coordsRange: < 1.12
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/08/12/4nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-3mwj-7vmq-w43pghsaADVISORY
- jenkins.io/security/advisory/2020-08-12/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-2236ghsaADVISORY
- github.com/jenkinsci/yet-another-build-visualizer-plugin/commit/0e6db61ef66f4ed4f2e580240e364f195b00ee6eghsaWEB
News mentions
1- Jenkins Security Advisory 2020-08-12Jenkins Security Advisories · Aug 12, 2020