Lucene search

K
osvGoogleOSV:CVE-2022-28145
HistoryMar 29, 2022 - 1:15 p.m.

CVE-2022-28145

2022-03-2913:15:08
Google
osv.dev
8
jenkins
toad edge plugin
xss

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.0%

Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.0%

Related for OSV:CVE-2022-28145