CVE-2022-27197: XSS
Published Mar 15, 2022
·Updated
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.
Affected Software
2 affected componentsFixes available
Jenkins Dashboard View Jenkins<2.18.1
maven/org.jenkins-ci.plugins:dashboard-view<2.18.1
2.18.1
Event History
Mar 15, 2022
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
Description
Mar 16, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for Jenkins Dashboard View Plugin?
The vulnerability ID for Jenkins Dashboard View Plugin is CVE-2022-27197.
2
What is the severity of CVE-2022-27197?
The severity of CVE-2022-27197 is medium with a CVSS score of 5.4.
3
How does the vulnerability in Jenkins Dashboard View Plugin manifest?
The vulnerability in Jenkins Dashboard View Plugin manifests as a stored cross-site scripting (XSS) vulnerability.
4
Which versions of Jenkins Dashboard View Plugin are affected by this vulnerability?
Jenkins Dashboard View Plugin version 2.18 and earlier are affected by this vulnerability.
5
How can the vulnerability in Jenkins Dashboard View Plugin be exploited?
The vulnerability in Jenkins Dashboard View Plugin can be exploited by attackers who are able to configure views in the application.