PT-2022-22040 · Jenkins · Jenkins

Published

2022-06-22

·

Updated

2024-03-06

·

CVE-2022-34173

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.340 through 2.355
Description The tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability. This issue is exploitable by attackers with Job/Configure permission.
Recommendations For versions 2.340 through 2.355, update to Jenkins 2.356 or later, which addresses this vulnerability by escaping the tooltip of the build button in list views.

Fix

Path traversal

XSS

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2022-34173
CVE-2022-34173
GHSA-6G4R-Q7QG-6QX6

Affected Products

Jenkins