cbcvebase.
CVE-2022-46684
published 2022-12-12

CVE-2022-46684: Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscheckmarx< 2022.4.32022.4.3
jenkinscheckmarx_plugin
jenkinscustom_build_properties_plugin
jenkinsgitea_plugin
jenkinsgoogle_login_plugin
jenkinsplot_plugin
jenkinssonar_gerrit_plugin
jenkinsspring_config_plugin
jenkins_projectjenkins_checkmarx_pluginunspecified – 2022.3.3