Description
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6786 | Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine. |
Github GHSA |
GHSA-f2j5-w76m-3rqh | Jenkins Anchore Container Image Scanner Plugin vulnerable to cross site scripting |
References
History
Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-28T15:20:31.122Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-41225
Updated: 2024-08-03T12:35:49.646Z
Status : Modified
Published: 2022-09-21T16:15:09.917
Modified: 2025-05-28T16:15:29.363
Link: CVE-2022-41225
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA