cbcvebase.
CVE-2022-38664
published 2022-08-23

CVE-2022-38664: Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a…

PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.59%
44.2th percentile
Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.

Affected

7 ranges
VendorProductVersion rangeFixed in
jenkinscollabnet_plugins_plugin
jenkinsgit_plugin
jenkinsjob_configuration_history<= 1165.v8cc9fd1f4597
jenkinsjob_configuration_history_plugin
jenkinskubernetes_continuous_deploy_plugin
jenkinsyaml_input_files_to_kubernetes_continuous_deploy_plugin
jenkins_projectjenkins_job_configuration_history_pluginunspecified – 1165.v8cc9fd1f4597
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.