Reflected Cross-Site Scripting in Jenkins Lucene-Search Plugin
CVE-2022-36922
6.1MEDIUM
What is CVE-2022-36922?
The Jenkins Lucene-Search Plugin, specifically version 370.v62a5f618cd3a and earlier, is susceptible to a reflected cross-site scripting vulnerability due to improper escaping of the search query parameter. This flaw allows attackers to inject malicious scripts, which can be executed in the context of the victim's browser when they view the search results page, leading to potential data theft or session hijacking.
Affected Version(s)
Jenkins Lucene-Search Plugin <= 370.v62a5f618cd3a