CVE-2022-20615
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 81.84% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jenkins/matrix project · oracle/communications cloud native core automated test suite
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2022/01/12/6Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/01/12/6Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.