Stored Cross-Site Scripting Flaw in Jenkins with Toad Edge Plugin
CVE-2022-28145
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 29 March 2022
What is CVE-2022-28145?
The Jenkins Continuous Integration platform, when used with the Toad Edge Plugin version 2.3 and earlier, is vulnerable to a stored cross-site scripting (XSS) attack. This vulnerability arises due to the absence of Content-Security-Policy headers in the report files served by Jenkins, allowing attackers with Item/Configure permissions, or those able to manipulate report contents, to inject malicious scripts. Exploiting this vulnerability can compromise the integrity of user data and affect web application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Continuous Integration with Toad Edge Plugin <= 2.3
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved