Cross-site scripting vulnerability in Jenkins - CVE-2022-34171 (MAC OS)ID: oval:org.secpod.oval:def:83355 | Date: (C)2022-08-24 (M)2023-12-03 |
Class: VULNERABILITY | Family: macos |
The host is installed with Jenkins LTS 2.332.1 through 2.332.3 or Jenkins rolling release 2.321 through 2.355 and is prone to a cross-site scripting vulnerability. A flaw is present in the application, which fails to handle an issue in the help icon as it does not escape the feature name that is part of its tooltip. Successful exploitation could allow attackers with Job/Configure permission to exploit the cross-site scripting (XSS) vulnerability existing in the application.
Platform: |
Apple Mac OS 14 |
Apple Mac OS 13 |
Apple Mac OS 12 |
Apple Mac OS X 10.15 |
Apple Mac OS X 10.10 |
Apple Mac OS X 10.11 |
Apple Mac OS X 10.12 |
Apple Mac OS X 10.13 |
Apple Mac OS X 10.14 |
Apple Mac OS 11 |
Product: |
Jenkins LTS |
Jenkins rolling release |