CVE-2022-41224

Severity
5.4MEDIUM
EPSS
3.4%
top 12.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateSep 22

Description

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

NVDjenkins/jenkins2.3672.370
CVEListV5jenkins_project/jenkins2.367unspecified+1
Mavenorg.jenkins-ci.main:jenkins-core2.3672.370

🔴Vulnerability Details

3
OSV
Jenkins vulnerable to stored cross site scripting in the I:helpIcon component2022-09-22
GHSA
Jenkins vulnerable to stored cross site scripting in the I:helpIcon component2022-09-22
CVEList
CVE-2022-41224: Jenkins 22022-09-21

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2022-09-212022-09-21
Red Hat
Jenkins: stored XSS in Jenkins2022-09-21
CVE-2022-41224 (MEDIUM CVSS 5.4) | Jenkins 2.367 through 2.369 (both i | cvebase.io