cbcvebase.
CVE-2022-46684
published 2022-12-12

CVE-2022-46684: Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting…

PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.46%
36.6th percentile
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscheckmarx< 2022.4.32022.4.3
jenkinscheckmarx_plugin
jenkinscustom_build_properties_plugin
jenkinsgitea_plugin
jenkinsgoogle_login_plugin
jenkinsplot_plugin
jenkinssonar_gerrit_plugin
jenkinsspring_config_plugin
jenkins_projectjenkins_checkmarx_pluginunspecified – 2022.3.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.