id: CVE-2020-2140
info:
name: Jenkins Audit Trail XSS
risk: Medium
params:
- root: "{{.BaseURL}}"
replicate:
ports: '8080'
prefixes: 'jenkins'
requests:
- method: GET
redirect: false
url: >-
{{.root}}/descriptorByName/AuditTrailPlugin/regexCheck?value=*j
sample
headers:
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55
detections:
- >-
StatusCode() == 200 && StringSearch("response", "sample") && StringSearch("response", "regular expression")
references:
- https://www.cvebase.com/cve/2020/2140