{"id":"CVE-2020-2137","aliases":["GHSA-6xxf-rwv4-mrjm"],"url":"https://o3.security/vulnerability/CVE-2020-2137","summary":"Stored XSS vulnerability in Jenkins Timestamper Plugin","details":"Timestamper Plugin 1.11.1 and earlier does not escape or sanitize the HTML formatting used to display the timestamps in console output for builds.\n\nThis results in a stored cross-site scripting vulnerability that can be exploited by users with Overall/Administer permission.\n\nTimestamper Plugin 1.11.2 sanitizes the HTML formatting for timestamps and only allows basic, safe HTML formatting.","published":"2020-03-09T16:15:12.890Z","modified":"2026-07-08T17:56:25.102530Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00702,"percentile":0.50205,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.plugins:timestamper","fixedVersion":"1.11.2"}],"fix":{"url":"https://github.com/jenkinsci/timestamper-plugin/commit/6637c3e599c330e03251005675beeadb46d8495b","label":"jenkinsci/timestamper-plugin@6637c3e"},"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/03/09/1"},{"type":"ADVISORY","url":"https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1784"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-2137"},{"type":"WEB","url":"https://github.com/jenkinsci/timestamper-plugin/commit/6637c3e599c330e03251005675beeadb46d8495b"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/timestamper-plugin"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:56:25.102530Z"}}