Reflected Cross-Site Scripting in Jenkins Lucene-Search Plugin
CVE-2022-36922
6.1MEDIUM
Summary
The Jenkins Lucene-Search Plugin, specifically version 370.v62a5f618cd3a and earlier, is susceptible to a reflected cross-site scripting vulnerability due to improper escaping of the search query parameter. This flaw allows attackers to inject malicious scripts, which can be executed in the context of the victim's browser when they view the search results page, leading to potential data theft or session hijacking.
Affected Version(s)
Jenkins Lucene-Search Plugin <= 370.v62a5f618cd3a
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved