First published: Wed Jun 22 2022(Updated: )
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | >=2.340<=2.355 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34173 is a vulnerability in Jenkins versions 2.340 through 2.355 that allows cross-site scripting (XSS) attacks through an unescaped HTML tooltip in the build button of list views.
CVE-2022-34173 has a severity rating of 6.1 (Medium).
Users of Jenkins versions between 2.340 and 2.355 (inclusive) are affected by CVE-2022-34173.
To fix CVE-2022-34173, upgrade Jenkins to a version beyond 2.355.
You can find more information about CVE-2022-34173 in the Jenkins security advisory for June 22, 2022.