First published: Tue Mar 15 2022(Updated: )
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:dashboard-view | <2.18.1 | 2.18.1 |
Jenkins Dashboard View | <2.18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Jenkins Dashboard View Plugin is CVE-2022-27197.
The severity of CVE-2022-27197 is medium with a CVSS score of 5.4.
The vulnerability in Jenkins Dashboard View Plugin manifests as a stored cross-site scripting (XSS) vulnerability.
Jenkins Dashboard View Plugin version 2.18 and earlier are affected by this vulnerability.
The vulnerability in Jenkins Dashboard View Plugin can be exploited by attackers who are able to configure views in the application.