Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-65924
HistoryJun 27, 2022 - 12:00 a.m.

Jenkins Cross-Site Scripting Vulnerability (CNVD-2022-65924)

2022-06-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

22.0%

Jenkins is an application of the Jenkins open source. An open source automation server Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins suffers from a cross-site scripting vulnerability that stems from the fact that the help icon does not escape the name of a feature that is part of its tooltip. An attacker could exploit the vulnerability to execute JavaScript code on the client side.