PT-2022-22040 · Jenkins · Jenkins
Published
2022-06-22
·
Updated
2024-03-06
·
CVE-2022-34173
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.340 through 2.355
Description
The tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability. This issue is exploitable by attackers with Job/Configure permission.
Recommendations
For versions 2.340 through 2.355, update to Jenkins 2.356 or later, which addresses this vulnerability by escaping the tooltip of the build button in list views.
Fix
Path traversal
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins