CVE-2022-34170
Summary
| CVE | CVE-2022-34170 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-23 17:15:00 UTC |
| Updated | 2023-11-03 02:52:00 UTC |
| Description | In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jenkins Security Advisory 2022-06-22 | CONFIRM | www.jenkins.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 502482 Alpine Linux Security Update for jenkins
- 690884 Free Berkeley Software Distribution (FreeBSD) Security Update for jenkins (25be46f0-f25d-11ec-b62a-00e081b7aa2d)
- 730532 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities (Jenkins Security Advisory 2022-06-22)
- 730533 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730534 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730535 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730540 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730545 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730546 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730547 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730549 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730554 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730555 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730557 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730558 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730559 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730560 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730561 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities
- 730562 Jenkins Multiple Cross-Site Scripting (XSS) Vulnerabilities