CVE-2022-34176 is a stored cross-site scripting (XSS) vulnerability affecting Jenkins JUnit Plugin versions 1119.va_a_5e9068da_d7 and earlier. This medium severity vulnerability (CVSS 5.4) allows attackers with Run/Update permissions to inject malicious scripts into unescaped test result descriptions, potentially impacting confidentiality and integrity. While the EPSS score indicates a higher than average exploit probability, there is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1119.va_a_5e9068da_d7CPE matchmatch criteria | cpe:2.3:a:jenkins:junit:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cross-site Scripting in Jenkins JUnit Plugin
Jun 24, 2022jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin
Jun 23, 2022Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
Jun 14, 2022