CVE-2022-45380 is a stored cross-site scripting (XSS) vulnerability affecting Jenkins JUnit Plugin versions 1159.v0b_396e1e07dd and earlier, where HTTP(S) URLs in test reports are unsafely converted to clickable links. This medium-severity vulnerability has a CVSS score of 5.4, indicating it can be exploited by attackers with Item/Configure permissions, requiring user interaction, and potentially leading to low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1160.vf1f01a_a_ea_b_7fCPE matchmatch criteria | cpe:2.3:a:jenkins:junit:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion
Nov 16, 2022jenkins-plugin/JUnit: Stored XSS vulnerability in JUnit Plugin
Nov 15, 2022Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Nov 8, 2022