S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-2140 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Jenkins Audit Trail Plugin affects v. 3.2 and earlier.

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
11
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-2140
6.1
CVSS

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jenkins Audit Trail Pluginby Jenkins project
unspecified
Updated Aug 21, 2026View on NVD →
Detail

Jenkins Audit Trail Plugin is a software tool commonly used for auditing purposes for businesses that use the Jenkins build system. The tool is designed to track system build logs, errors and configuration files. It offers an accountability feature that tracks the origin of a change in the system and when it occurred. This feature can be highly valuable for businesses, particularly in cases of system breaches or unauthorized modifications.

One of the significant challenges that Jenkins Audit Trail Plugin faces is the CVE-2020-2140 vulnerability. This vulnerability is caused by the software's failure to escape the message fields required when validating URL patterns. As a result, attackers can inject malicious code into these fields in a reflected cross-site scripting (XSS) attack. 

When exploited, this vulnerability can cause widespread damage to businesses that utilize the plugin. Attackers can gain unauthorized access to sensitive business data and manipulate it. They can extract sensitive customer information and perform fraudulent actions such as making unauthorized transactions. They can also add or remove users from the system and delete or tamper with critical files.

Thanks to the pro features of the s4e.io platform, businesses can quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive and easy-to-use vulnerability scanning tool that can detect and mitigate vulnerabilities in popular software tools such as Jenkins Audit Trail Plugin. By subscribing to this platform, businesses can ensure that their systems remain secure from potential cyber threats.

 

REFERENCES

 

Solution Advice

To prevent this vulnerability, there are several precautions that businesses can take. These include:

  • Updating Jenkins Audit Trail Plugin to the latest version
  • Configuring the plugin to restrict URL patterns that can be used for logging
  • Regularly scanning for cross-site scripting vulnerabilities
  • Limiting system access permissions to only authorized personnel
  • Using firewall and security protocols that detect and block malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.