Related Vulnerabilities: CVE-2022-34176  

Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

Description

The MITRE CVE dictionary describes this issue as:

Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

Additional Information

  • Bugzilla 2103548: CVE-2022-34176 jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • FAQ: Frequently asked questions about CVE-2022-34176