Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-65923
HistoryJun 27, 2022 - 12:00 a.m.

Jenkins Cross-Site Scripting Vulnerability (CNVD-2022-65923)

2022-06-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.001 Low

EPSS

Percentile

22.0%

Jenkins is a Jenkins open source application. Jenkins, an open source automation server, provides hundreds of plugins to support building, deploying, and automating any project.A cross-site scripting vulnerability exists in Jenkins versions 2.320 through 2.355, which stems from a symbol-based icon that fails to escape previously escaped “tooltip” parameter values. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

CPENameOperatorVersion
Jenkins Jenkins >=2.340,le2.355