PT-2022-22037 · Jenkins · Jenkins

Published

2022-06-22

·

Updated

2024-03-06

·

CVE-2022-34170

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.320 through 2.355 Jenkins LTS versions 2.332.1 through 2.332.3
Description The help icon in Jenkins does not escape the feature name that is part of its tooltip, resulting in a cross-site scripting (XSS) vulnerability. This issue is exploitable by attackers with Job/Configure permission. The vulnerability effectively undoes the fix for a previous security issue.
Recommendations For Jenkins versions 2.320 through 2.355, update to version 2.356 or later to resolve the issue. For Jenkins LTS versions 2.332.1 through 2.332.3, update to version 2.332.4 or later, or version 2.346.1 or later, to resolve the issue.

Fix

Path traversal

XSS

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2022-34170
CVE-2022-34170
GHSA-62WF-24C4-8R76

Affected Products

Jenkins