Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.plugins/jobConfigHistory
  4. ›
  5. CVE-2022-38664

CVE-2022-38664: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

August 24, 2022 (updated November 28, 2022)

Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.

References

  • www.openwall.com/lists/oss-security/2022/08/23/2
  • github.com/advisories/GHSA-28w4-h56g-grg7
  • nvd.nist.gov/vuln/detail/CVE-2022-38664
  • www.jenkins.io/security/advisory/2022-08-23/

Code Behaviors & Features

Detect and mitigate CVE-2022-38664 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1165.v8cc9fd1f4597

Fixed versions

  • 1166.vc9f255f45b

Solution

Upgrade to version 1166.vc9f255f45b or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

maven/org.jenkins-ci.plugins/jobConfigHistory/CVE-2022-38664.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:54 +0000.