CVE-2022-34173: XSS
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34173?
CVE-2022-34173 is a vulnerability in Jenkins versions 2.340 through 2.355 that allows cross-site scripting (XSS) attacks through an unescaped HTML tooltip in the build button of list views.
How severe is CVE-2022-34173?
CVE-2022-34173 has a severity rating of 6.1 (Medium).
Who is affected by CVE-2022-34173?
Users of Jenkins versions between 2.340 and 2.355 (inclusive) are affected by CVE-2022-34173.
How can I fix CVE-2022-34173?
To fix CVE-2022-34173, upgrade Jenkins to a version beyond 2.355.
Where can I find more information about CVE-2022-34173?
You can find more information about CVE-2022-34173 in the Jenkins security advisory for June 22, 2022.