PT-2022-22037 · Jenkins · Jenkins
Published
2022-06-22
·
Updated
2024-03-06
·
CVE-2022-34170
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.320 through 2.355
Jenkins LTS versions 2.332.1 through 2.332.3
Description
The help icon in Jenkins does not escape the feature name that is part of its tooltip, resulting in a cross-site scripting (XSS) vulnerability. This issue is exploitable by attackers with Job/Configure permission. The vulnerability effectively undoes the fix for a previous security issue.
Recommendations
For Jenkins versions 2.320 through 2.355, update to version 2.356 or later to resolve the issue.
For Jenkins LTS versions 2.332.1 through 2.332.3, update to version 2.332.4 or later, or version 2.346.1 or later, to resolve the issue.
Fix
Path traversal
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins