Back

HIGH

Jenkins: stored XSS in Jenkins

Published Sep 21, 2022

Description

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

Affected products

Remediation

Red Hat statement

This vulnerability affects Jenkins version 2.367 through 2.369 (both inclusive). Red Hat products use Jenkins LTS which is NOT affected by this vulnerability.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jenkins
Published Sep 21, 2022
Updated May 28, 2025
Reserved Sep 21, 2022
CISA Vulnrichment
Updated May 28, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 21, 2022
ENISA EUVD
Assigner jenkins
Published Sep 21, 2022
Updated May 28, 2025
Exploited since n/a
EUVD-2022-6980 GHSA-XPVP-H73C-M9RQ