VDB
CVE-2022-34173
CVE-2022-34173
PUBLISHED
CVSS 5.400000095367432 MEDIUM
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
EPSS 1.44% · 72.2th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.44%
72.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | jenkins | 2.340.0 |
| Bitnami | jenkins | 2.340.0 |
Timeline
- Jun 22, 2022 CVE Published
- Jun 23, 2022 EPSS Score
- Aug 11, 2022 EPSS Score
- Nov 16, 2022 EPSS Score
- Jan 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 10, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Sep 2, 2023 EPSS Score
- Oct 20, 2023 EPSS Score
- Jan 25, 2024 EPSS Score
- Mar 13, 2024 EPSS Score