CVE-2022-34170
Cross-site Scripting vulnerability in Jenkins
8.0
HIGH
CVSS 3.1
EPSS 1.4%
Description
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
How to fix CVE-2022-34170
To remediate CVE-2022-34170, upgrade the affected package to a fixed version below.
- —upgrade to 2.355.1 or later
- —upgrade to 2.356 or later
Is CVE-2022-34170 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 2.320.0, < 2.355.1
- >= 2.350, < 2.356
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |