PT-2022-27482 · Jenkins · Jenkins Junit Plugin+1

Wadeck Follonier

·

Published

2022-11-15

·

Updated

2023-11-22

·

CVE-2022-45380

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins JUnit Plugin versions 1159.v0b 396e1e07dd and earlier
Description The issue is related to the conversion of HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability. This vulnerability is exploitable by attackers with Item/Configure permission.
Recommendations For Jenkins JUnit Plugin versions 1159.v0b 396e1e07dd and earlier, update to a version that no longer converts URLs to clickable links, such as version 1160.vf1f01a a ea b 7f or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-45380
GHSA-298R-5C48-7Q2R
RHSA-2023:0560
RHSA-2023:0777

Affected Products

Jenkins
Jenkins Junit Plugin