CVE-2022-20615

Severity
5.4MEDIUM
EPSS
2.9%
top 13.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateApr 15

Description

Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Patches

🔴Vulnerability Details

3
OSV
Stored XSS vulnerability in Matrix Project Plugin2022-01-13
GHSA
Stored XSS vulnerability in Matrix Project Plugin2022-01-13
CVEList
CVE-2022-20615: Jenkins Matrix Project Plugin 12022-01-12

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Jenkins Matrix Project) — CVE-2022-206152022-04-15
Jenkins
Jenkins Security Advisory 2022-01-122022-01-12
Red Hat
jenkins-2-plugins/matrix-project: does not escape HTML metacharacters which could result in XSS2022-01-12