CVE-2022-34170: XSS
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Other sources
Since Jenkins 2.320 and LTS 2.332.1, help icon tooltips no longer escape the feature name, effectively undoing the fix for SECURITY-1955.
This vulnerability is known to be exploitable by attackers with Job/Configure permission.
Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability, the feature name in help icon tooltips is now escaped.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34170?
CVE-2022-34170 is a cross-site scripting (XSS) vulnerability in Jenkins.
What is the severity of CVE-2022-34170?
CVE-2022-34170 has a severity rating of 6.1 (Medium).
Which versions of Jenkins are affected by CVE-2022-34170?
Jenkins versions 2.320 through 2.355 and LTS versions 2.332.1 through 2.332.3 are affected by CVE-2022-34170.
How can I fix CVE-2022-34170?
To fix CVE-2022-34170, you should update Jenkins to a version that includes the security fix, as mentioned in the Jenkins security advisory (see reference).
Where can I find more information about CVE-2022-34170?
You can find more information about CVE-2022-34170 in the Jenkins security advisory (see reference).