CVE-2022-34176
published 2022-06-23CVE-2022-34176: Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS)…
PriorityP342medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
76.88%
99.5th percentile
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | agent_server_parameter_plugin | — | — |
| jenkins | beaker_builder_plugin | — | — |
| jenkins | convertigo_mobile_platform_plugin | — | — |
| jenkins | crx_content_package_deployer_plugin | — | — |
| jenkins | date_parameter_plugin | — | — |
| jenkins | dynamic_extended_choice_parameter_plugin | — | — |
| jenkins | easyqa_plugin | — | — |
| jenkins | embeddable_build_status_plugin | — | — |
| jenkins | filesystem_list_parameter_plugin | — | — |
| jenkins | hidden_parameter_plugin | — | — |
| jenkins | image_tag_parameter_plugin | — | — |
| jenkins | improper_authorization_in_embeddable_build_status_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | jenkins_ci_server_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | jianliao_notification_plugin | — | — |
| jenkins | junit | <= 1119.va_a_5e9068da_d7 | — |
| jenkins | junit_plugin | — | — |
| jenkins | maven_metadata_plugin | — | — |
| jenkins | nested_view_plugin | — | — |
| jenkins | ns-nd_integration_performance_publisher_plugin | — | — |
| jenkins | orchestrator_plugin | — | — |
| jenkins | package_version_plugin | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Stored XSS vulnerability exists in Jenkins JUnit Plugin versions up to and including 1119.va_a_5e9068da_d7 — descriptions of test results are not escaped, allowing injection of arbitrary HTML/script code ↗
- →Exploitation requires Run/Update permission — monitor for unexpected HTML or script content injected into Jenkins test result descriptions by users holding this permission level ↗
- ·Red Hat has marked the affected package (jenkins-2-plugins) in Red Hat OpenShift Container Platform 3.11 as 'Will not fix' — deployments on this platform remain permanently vulnerable unless mitigated externally ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin
vendor_redhat·2022-06-23·CVSS 5.4
CVE-2022-34176 [MEDIUM] CWE-79 jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin
jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
A flaw was found in the JUnit Jenkins plugin. The manipulation with an unknown input leads to a Cross-site scripting vulnerability, impacting the integrity. This flaw allows an attacker to inject arbitrary HTML and script code into the website.
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.11) - Will not fix
Jenkins
Jenkins Security Advisory 2022-06-22
vendor_jenkins·2022-06-22·CVSS 5.4
CVE-2017-2601 [MEDIUM] Jenkins Security Advisory 2022-06-22
Title: Jenkins Security Advisory 2022-06-22
Jenkins Security Advisory 2022-06-22
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Agent Server Parameter
Plugin
Beaker builder
Plugin
Convertigo Mobile Platform
Plugin
CRX Content Package Deployer
Plugin
Date Parameter
Plugin
Dynamic
Microsoft
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Up
vendor_msrc·2022-06-14·CVSS 5.4
CVE-2022-34176 [MEDIUM] CWE-79 Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Up
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we
OSV
Cross-site Scripting in Jenkins JUnit Plugin
osv·2022-06-24
CVE-2022-34176 [HIGH] Cross-site Scripting in Jenkins JUnit Plugin
Cross-site Scripting in Jenkins JUnit Plugin
JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
JUnit Plugin 1119.1121.vc43d0fc45561 applies the configured markup formatter to descriptions of test results.
GHSA
Cross-site Scripting in Jenkins JUnit Plugin
ghsa·2022-06-24
CVE-2022-34176 [HIGH] CWE-79 Cross-site Scripting in Jenkins JUnit Plugin
Cross-site Scripting in Jenkins JUnit Plugin
JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
JUnit Plugin 1119.1121.vc43d0fc45561 applies the configured markup formatter to descriptions of test results.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-23
Published