S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-2096 Scanner

CVE-2020-2096 scanner - Cross-Site Scripting (XSS) vulnerability in Jenkins Gitlab Hook Plugin

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-2096
6.1
CVSS

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jenkins Gitlab Hook Pluginby Jenkins project
unspecified
Updated Aug 21, 2026View on NVD →
Detail

Jenkins Gitlab Hook Plugin is a software tool designed to help developers improve their workflow by automating the process of building and testing code changes. The plugin acts as a bridge between Jenkins and GitLab, allowing developers to trigger builds of their code and receive notifications of the results directly within their preferred software development tools. With Jenkins Gitlab Hook Plugin, developers can save time and ensure code quality by automating these essential tasks.

However, the plugin was found to have a serious vulnerability, identified as CVE-2020-2096. This flaw allows attackers to exploit the build_now endpoint by injecting malicious code in the project name. This results in a reflected cross-site scripting (XSS) attack that can compromise any user who clicks on the link or views the malicious page. The vulnerability was confirmed in Jenkins Gitlab Hook Plugin 1.4.2 and earlier versions.

When exploited, this vulnerability can lead to serious consequences. An attacker can steal sensitive information from users, such as passwords, cookies, and login credentials, by tricking them into clicking on a malicious link. Additionally, this vulnerability can be used to launch phishing attacks, spread malware, or take control of victim's computers.

s4e.io, which provides in-depth security vulnerability audits for web applications, can quickly find and help users resolve this vulnerability and others like it. With s4e.io's professional tools and expertise, users can ensure their digital assets can remain secure and protected against threats. By identifying vulnerabilities and offering tailored solutions, s4e.io can assist users in safeguarding their web applications from threats like CVE-2020-2096.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users need to take a few precautions, including:

  • Update to the latest version of Jenkins Gitlab Hook Plugin that patches the vulnerability
  • Stay informed about security updates and new vulnerabilities that are discovered
  • Use anti-virus software and firewalls to protect their systems from malware
  • Configure the plugin to only allow trusted users and prevent access for anonymous users.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.