CVE-2022-34787
CVE-2022-34787
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
30 jun 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
Productos afectados
Jenkins project · Jenkins Project Inheritance Plugin