CVE-2022-34170
Published on: Not Yet Published
Last Modified on: 06/23/2022 05:19:00 PM UTC
Certain versions of Jenkins from Jenkins Project contain the following vulnerability:
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
- CVE-2022-34170 has been assigned by
[email protected] to track the vulnerability
- Affected Vendor/Software:
Jenkins project - Jenkins version >= 2.320
- Affected Vendor/Software:
Jenkins project - Jenkins version <= 2.355
- Affected Vendor/Software:
Jenkins project - Jenkins version >= LTS 2.332.1
- Affected Vendor/Software:
Jenkins project - Jenkins version <= LTS 2.332.3
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Jenkins Security Advisory 2022-06-22 | www.jenkins.io text/html |
![]() |
Related QID Numbers
- 690884 Free Berkeley Software Distribution (FreeBSD) Security Update for jenkins (25be46f0-f25d-11ec-b62a-00e081b7aa2d)
- 730532 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730533 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730534 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730535 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730540 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730545 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
Known Affected Software
Vendor | Product | Version |
---|---|---|
Jenkins Project | Jenkins | >= 2.320 |
Jenkins Project | Jenkins | <= 2.355 |
Jenkins Project | Jenkins | >= LTS 2.332.1 |
Jenkins Project | Jenkins | <= LTS 2.332.3 |
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-34170 : In Jenkins 2.320 through 2.355 both inclusive and LTS 2.332.1 through LTS 2.332.3 both inclusiv… twitter.com/i/web/status/1… | 2022-06-22 14:44:53 |
![]() |
Jenkins LTS and weekly cross-site scripting | CVE-2022-34170 - redpacketsecurity.com/jenkins-lts-an… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber | 2022-06-23 09:02:27 |
![]() |
Jenkins - CVE-2022-34170: jenkins.io/security/advis… | 2022-06-23 19:00:08 |
![]() |
CVE-2022-34170 | Jenkins up to LTS 2.332.3/2.355 Help Icon cross site scripting A vulnerability classified as probl… twitter.com/i/web/status/1… | 2022-06-24 07:50:26 |