CVE-2022-20615: XSS
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Other sources
Jenkins Matrix Project Plugin prior to 1.20 and 1.18.1 does not escape HTML metacharacters in node and label names, and label descriptions.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Matrix Project Plugin 1.20 and 1.18.1 escapes HTML metacharacters in node and label names, and label descriptions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-20615?
CVE-2022-20615 is a vulnerability in Jenkins Matrix Project Plugin versions 1.19 and earlier that allows for stored cross-site scripting (XSS) attacks.
How severe is CVE-2022-20615?
CVE-2022-20615 has a severity rating of 5.4 (medium).
How does CVE-2022-20615 affect Jenkins Matrix Project Plugin?
CVE-2022-20615 affects Jenkins Matrix Project Plugin versions 1.19 and earlier, allowing for stored cross-site scripting (XSS) attacks.
How can I fix CVE-2022-20615?
To fix CVE-2022-20615, upgrade Jenkins Matrix Project Plugin to version 1.20 or later.
Where can I find more information about CVE-2022-20615?
You can find more information about CVE-2022-20615 at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2022/01/12/6), [Link 2](https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017), [Link 3](https://www.oracle.com/security-alerts/cpuapr2022.html).