Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05039
HistoryJan 16, 2022 - 12:00 a.m.

Jenkins Cross-Site Scripting Vulnerability (CNVD-2022-05039)

2022-01-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
8

0.001 Low

EPSS

Percentile

22.0%

Jenkins is a Jenkins open source application. An open source automation server Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins Publish Over SSH Plugin in version 1.22 and earlier has a cross-site scripting vulnerability that stems from the lack of data validation filtering of SSH server names on user-supplied data and output. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

CPENameOperatorVersion
jenkins publish over ssh pluginle1.22

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-05039