CVE-2022-34182

HIGH8.8EPSS 14.8%

Reflected Cross-site Scripting in Jenkins Nested View Plugin

Published: 6/24/2022Modified: 11/8/2023

Description

Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. Nested View Plugin 1.26 escapes search parameters

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (4)