First published: Wed Jun 22 2022(Updated: )
Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Nested View | >=1.20<=1.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34182 has a medium severity rating due to its potential to allow reflected cross-site scripting (XSS) attacks.
To fix CVE-2022-34182, update the Jenkins Nested View Plugin to version 1.26 or later.
CVE-2022-34182 is a reflected cross-site scripting (XSS) vulnerability.
Versions 1.20 through 1.25 of the Jenkins Nested View Plugin are affected by CVE-2022-34182.
If you are using Jenkins Nested View Plugin versions 1.20 to 1.25, your environment is susceptible to CVE-2022-34182.