3.5
CVSSv2

CVE-2022-28145

Published: 29/03/2022 Updated: 17/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Jenkins Continuous Integration with Toad Edge Plugin 2.3 and previous versions does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins continuous integration with toad edge

Vendor Advisories

Jenkins Continuous Integration with Toad Edge Plugin 23 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents ...