Jenkins: stored XSS in Jenkins
Published Sep 21, 2022
8.0
HIGHCVSS 3.1
EPSS 1.06%
Description
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.
Affected products
-
- Version 2.367StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<=2.369
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins | n/a |
|
No data.
Red Hat OpenShift Container Platform 3.11
jenkins
Not affected
Red Hat OpenShift Container Platform 4
jenkins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability affects Jenkins version 2.367 through 2.369 (both inclusive). Red Hat products use Jenkins LTS which is NOT affected by this vulnerability.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-41224 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2128968 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6980 Advisory
- https://github.com/advisories/GHSA-xpvp-h73c-m9rq Advisory
- https://github.com/jenkinsci/jenkins/commit/84f41d2921023374dedb7d6f12d47eaf7790b7eb
- https://nvd.nist.gov/vuln/detail/CVE-2022-41224
- https://www.cve.org/CVERecord?id=CVE-2022-41224
- https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2886 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.