VDB

CVE-2022-34173

CVE-2022-34173 PUBLISHED CVSS 5.400000095367432 MEDIUM

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

EPSS 1.44% · 72.2th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.44%
72.2th percentile

Affected Products

VendorProductVersions
Bitnamijenkins2.340.0
Bitnamijenkins2.340.0

Timeline

  • Jun 22, 2022 CVE Published
  • Jun 23, 2022 EPSS Score
  • Aug 11, 2022 EPSS Score
  • Nov 16, 2022 EPSS Score
  • Jan 3, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 10, 2023 EPSS Score
  • May 28, 2023 EPSS Score
  • Sep 2, 2023 EPSS Score
  • Oct 20, 2023 EPSS Score
  • Jan 25, 2024 EPSS Score
  • Mar 13, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›