CVE-2022-20615
published 2022-01-12CVE-2022-20615: Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored…
PriorityP342medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
81.84%
99.6th percentile
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory_plugin | — | — |
| jenkins | badge_plugin | — | — |
| jenkins | bitbucket_branch_source_plugin | — | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | conjur_secrets_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | debian_package_builder_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | hashicorp_vault_plugin | — | — |
| jenkins | ids_in_bitbucket_branch_source_plugin | — | — |
| jenkins | improper_credentials_masking_in_hashicorp_vault_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_ui_requesting_they_update_the_plugin | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | mailer_plugin | — | — |
| jenkins | matrix_project | <= 1.19 | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins | metrics_plugin | — | — |
| jenkins | publish_over_ssh_plugin | — | — |
| jenkins | ssh_agent_plugin | — | — |
| jenkins | warnings_plugin | — | — |
| jenkins_project | jenkins_matrix_project_plugin | unspecified – 1.19 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Stored XSS is injected via node names, label names, or label descriptions in Jenkins Matrix Project Plugin — monitor for unescaped HTML metacharacters (e.g., <, >, ", ') in these fields ↗
- →Exploitation requires Agent/Configure permission — alert on privilege assignments to this role in Jenkins, especially for untrusted users ↗
- →Audit Jenkins Matrix Project Plugin version; versions 1.19 and earlier are vulnerable — flag installations of jenkins-2-plugins on OpenShift Container Platform 3.11 and 4 ↗
- ·Exploitation is only possible for authenticated users holding Agent/Configure permission; attack surface is limited to privileged internal users, not anonymous/remote attackers ↗
- ·Red Hat has marked jenkins-2-plugins on OpenShift Container Platform 3.11 as 'Will not fix', meaning patching may not be available for that platform version ↗
- ·Oracle classifies this as non-remotely exploitable despite being an HTTP-protocol vulnerability, consistent with the requirement for an authenticated session with specific permissions ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_oracle5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Jenkins Matrix Project) — CVE-2022-20615
vendor_oracle·2022-04-15·CVSS 5.4
CVE-2022-20615 [MEDIUM] Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Jenkins Matrix Project) — CVE-2022-20615
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Jenkins Matrix Project) vulnerability
CVE: CVE-2022-20615
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Jenkins
Jenkins Security Advisory 2022-01-12
vendor_jenkins·2022-01-12·CVSS 4.3
CVE-2022-20612 [MEDIUM] Jenkins Security Advisory 2022-01-12
Title: Jenkins Security Advisory 2022-01-12
Jenkins Security Advisory 2022-01-12
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Active Directory
Plugin
Badge
Plugin
batch task
Plugin
Bitbucket Branch Source
Plugin
Configuration as Code
Plugin
Conjur Secrets
Plugin
Credential
Red Hat
jenkins-2-plugins/matrix-project: does not escape HTML metacharacters which could result in XSS
vendor_redhat·2022-01-12·CVSS 5.4
CVE-2022-20615 [MEDIUM] CWE-79 jenkins-2-plugins/matrix-project: does not escape HTML metacharacters which could result in XSS
jenkins-2-plugins/matrix-project: does not escape HTML metacharacters which could result in XSS
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
A stored Cross-site scripting (XSS) vulnerability was found in the Jenkins Matrix Project plugin. There are no escape HTML metacharacters in node, label names, and label descriptions, which allows an attacker with Agent/Configure permissions to perform an XSS attack.
Package: jenkins (Red Hat OpenShift Container Platform 3.11) - Affected
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.11) - Will not fix
Package: jenkins (Re
OSV
Stored XSS vulnerability in Matrix Project Plugin
osv·2022-01-13
CVE-2022-20615 [MEDIUM] Stored XSS vulnerability in Matrix Project Plugin
Stored XSS vulnerability in Matrix Project Plugin
Jenkins Matrix Project Plugin prior to 1.20 and 1.18.1 does not escape HTML metacharacters in node and label names, and label descriptions.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Matrix Project Plugin 1.20 and 1.18.1 escapes HTML metacharacters in node and label names, and label descriptions.
GHSA
Stored XSS vulnerability in Matrix Project Plugin
ghsa·2022-01-13
CVE-2022-20615 [MEDIUM] CWE-79 Stored XSS vulnerability in Matrix Project Plugin
Stored XSS vulnerability in Matrix Project Plugin
Jenkins Matrix Project Plugin prior to 1.20 and 1.18.1 does not escape HTML metacharacters in node and label names, and label descriptions.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Matrix Project Plugin 1.20 and 1.18.1 escapes HTML metacharacters in node and label names, and label descriptions.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/01/12/6https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.openwall.com/lists/oss-security/2022/01/12/6https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017https://www.oracle.com/security-alerts/cpuapr2022.html
2022-01-12
Published