Stored Cross-Site Scripting Vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin
CVE-2022-34191
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 23 June 2022
What is CVE-2022-34191?
The NS-ND Integration Performance Publisher Plugin for Jenkins prior to version 4.8.0.77 contains a vulnerability where it fails to properly escape the names of NetStorm Test parameters. This oversight allows attackers with Item/Configure permissions to potentially exploit the application by injecting malicious scripts that can be executed in the context of the user's session, leading to unauthorized data access and other harmful actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins NS-ND Integration Performance Publisher Plugin <= 4.8.0.77
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved