Cross-site Scripting vulnerability in Jenkins
High severity
GitHub Reviewed
Published
Jun 24, 2022
to the GitHub Advisory Database
•
Updated Mar 13, 2024
Package
Affected versions
>= 2.350, < 2.356
>= 2.320, < 2.332.4
>= 2.346, < 2.346.1
Patched versions
2.356
2.332.4
2.346.1
Description
Published by the National Vulnerability Database
Jun 23, 2022
Published to the GitHub Advisory Database
Jun 24, 2022
Reviewed
Dec 6, 2022
Last updated
Mar 13, 2024
Since Jenkins 2.320 and LTS 2.332.1, help icon tooltips no longer escape the feature name, effectively undoing the fix for SECURITY-1955.
This vulnerability is known to be exploitable by attackers with Job/Configure permission.
Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability, the feature name in help icon tooltips is now escaped.
References