Reflected Cross-Site Scripting in Jenkins Lucene-Search Plugin
CVE-2022-36922

6.1MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
27 July 2022

Summary

The Jenkins Lucene-Search Plugin, specifically version 370.v62a5f618cd3a and earlier, is susceptible to a reflected cross-site scripting vulnerability due to improper escaping of the search query parameter. This flaw allows attackers to inject malicious scripts, which can be executed in the context of the victim's browser when they view the search results page, leading to potential data theft or session hijacking.

Affected Version(s)

Jenkins Lucene-Search Plugin <= 370.v62a5f618cd3a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.