PT-2022-15853 · Jenkins · Jenkins Publish Over Ssh Plugin+1

Kevin Guerroudj

·

Published

2022-01-12

·

Updated

2023-11-15

·

CVE-2022-23110

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Publish Over SSH Plugin versions 1.22 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. This occurs because the SSH server name is not properly escaped, allowing attackers with Overall/Administer permission to exploit the vulnerability.
Recommendations For Jenkins Publish Over SSH Plugin versions 1.22 and earlier, update to a version later than 1.22 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23110
GHSA-FJPM-HF7C-XGC2

Affected Products

Jenkins
Jenkins Publish Over Ssh Plugin