PT-2022-22039 · Jenkins · Jenkins
Published
2022-06-22
·
Updated
2024-03-06
·
CVE-2022-34172
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.340 through 2.355
Description
The issue arises from symbol-based icons unescaping previously escaped values of
tooltip parameters, resulting in a cross-site scripting (XSS) vulnerability. This vulnerability is known to be exploitable by attackers with Job/Configure permission.Recommendations
For versions 2.340 through 2.355, update to Jenkins 2.356 or apply one of the following LTS updates: 2.332.4 or 2.346.1, as these versions address the vulnerability by ensuring symbol-based icons no longer unescape values of
tooltip parameters.
As a temporary workaround, consider restricting access to symbol-based icons or limiting the ability to configure tooltip parameters until the update can be applied.Fix
Path traversal
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins