Lucene search

K
cve[email protected]CVE-2022-36922
HistoryJul 27, 2022 - 3:15 p.m.

CVE-2022-36922

2022-07-2715:15:13
CWE-79
web.nvd.nist.gov
51
2
cve-2022-36922
jenkins
lucene-search plugin
xss
vulnerability
nvd

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

33.7%

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the ‘search’ result page, resulting in a reflected cross-site scripting (XSS) vulnerability.

Affected configurations

NVD
Node
jenkinslucene-searchRange370.v62a5f618cd3ajenkins

CNA Affected

[
  {
    "product": "Jenkins Lucene-Search Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "370.v62a5f618cd3a",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 370.v62a5f618cd3a",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

33.7%