CVE-2022-34184: XSS
Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34184?
The severity of CVE-2022-34184 is classified as medium due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-34184?
To fix CVE-2022-34184, you should upgrade to Jenkins Crx Content Package Deployer Plugin version 1.10 or later.
Who is affected by CVE-2022-34184?
CVE-2022-34184 affects users of Jenkins with the Crx Content Package Deployer Plugin version 1.9 and earlier.
What kind of attack does CVE-2022-34184 allow?
CVE-2022-34184 allows attackers with Item/Configure permission to exploit stored cross-site scripting (XSS) vulnerabilities.
What are the implications of CVE-2022-34184?
The implications of CVE-2022-34184 include the potential for attackers to execute scripts in the context of users accessing the vulnerable Jenkins instance.