In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2022-06-22T14:40:50

Updated: 2024-08-03T08:16:17.207Z

Reserved: 2022-06-21T00:00:00

Link: CVE-2022-34170

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-23T17:15:15.253

Modified: 2023-11-03T02:52:35.667

Link: CVE-2022-34170

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-06-22T00:00:00Z

Links: CVE-2022-34170 - Bugzilla