In Jenkins 2.340 through 2.355 (both... CVE-2022-34173

4.3 AV AC AU C I A
发布: 2022-06-23
修订: 2024-11-21

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息