CVE-2022-43409: XSS

Published Oct 19, 2022
·
Updated

A Cross-site scripting (XSS) vulnerability was found in a Jenkins plugin. This issue may allow an authenticated remote attacker to create Pipelines.

Other sources

Jenkins Pipeline: Supporting APIs Plugin 838.va3a087b4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

Pipeline: Supporting APIs Plugin provides a feature to add hyperlinks, that send POST requests when clicked, to build logs. These links are used by Pipeline: Input Step Plugin to allow users to proceed or abort the build, or by Pipeline: Job Plugin to allow users to forcibly terminate the build after aborting it.

Pipeline: Supporting APIs Plugin 838.va3a087b4055b and earlier does not sanitize or properly encode URLs of these hyperlinks in build logs.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

Pipeline: Supporting APIs Plugin 839.v35e2736cfd5c properly encodes URLs of these hyperlinks in build logs.

Affected Software

8 affected componentsFixes available
redhat/jenkins<2-plugins-0:4.11.1683009941-1.el8
2-plugins-0:4.11.1683009941-1.el8
redhat/jenkins<2-plugins-0:4.12.1675702407-1.el8
2-plugins-0:4.12.1675702407-1.el8
redhat/jenkins<2-plugins-0:4.10.1675144701-1.el8
2-plugins-0:4.10.1675144701-1.el8
redhat/jenkins<2-plugins-0:4.9.1675668922-1.el8
2-plugins-0:4.9.1675668922-1.el8
maven/org.jenkins-ci.plugins.workflow:workflow-support<839.v35e2736cfd5c
839.v35e2736cfd5c
redhat/Pipeline Supporting APIs Plugin<839.
839.
Jenkins Pipeline\<=838.va_3a_087b_4055b
Jenkins Supporting Apis Jenkins<=838.va_3a_087b_4055b

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.11.1683009941-1.el8
  2. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.12.1675702407-1.el8
  3. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.10.1675144701-1.el8
  4. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.9.1675668922-1.el8
  5. Upgrade

    Upgrade maven/org.jenkins-ci.plugins.workflow:workflow-support to a version that resolves this vulnerability.

    Fixed in 839.v35e2736cfd5c
  6. Upgrade

    Upgrade redhat/Pipeline Supporting APIs Plugin to a version that resolves this vulnerability.

    Fixed in 839.

Event History

Oct 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
07:00 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-43409?

CVE-2022-43409 is classified as a medium severity Cross-site Scripting (XSS) vulnerability.

2

How do I fix CVE-2022-43409?

To fix CVE-2022-43409, update the Jenkins Pipeline: Supporting APIs Plugin to version 839.v35e2736cfd5c or later.

3

What causes CVE-2022-43409?

CVE-2022-43409 is caused by insufficient sanitization and encoding of URLs in hyperlinks that send POST requests.

4

Who is affected by CVE-2022-43409?

CVE-2022-43409 affects users of the Jenkins Pipeline: Supporting APIs Plugin versions 838.va_3a_087b_4055b and earlier.

5

Can CVE-2022-43409 be exploited remotely?

Yes, CVE-2022-43409 can be exploited by an authenticated remote attacker to create potentially harmful Pipelines.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203