Description
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6980 | Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component. |
Github GHSA |
GHSA-xpvp-h73c-m9rq | Jenkins vulnerable to stored cross site scripting in the I:helpIcon component |
References
History
Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-28T15:21:09.111Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-41224
Updated: 2024-08-03T12:35:49.640Z
Status : Modified
Published: 2022-09-21T16:15:09.710
Modified: 2025-05-28T16:15:28.990
Link: CVE-2022-41224
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA