Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-34171
HistoryJun 22, 2022 - 2:40 p.m.

CVE-2022-34171

2022-06-2214:40:51
jenkins
www.cve.org
1

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the ‘title’ attribute of ‘l:ionicon’ (until Jenkins 2.334) and ‘alt’ attribute of ‘l:icon’ (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.

CNA Affected

[
  {
    "product": "Jenkins",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "2.321",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "2.355",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "LTS 2.332.1",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "LTS 2.332.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%