Vulnerability Details CVE-2022-34786
Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.153
EPSS Ranking 94.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2022-34786
-
cpe:2.3:a:jenkins:rich_text_publisher:1.0
-
cpe:2.3:a:jenkins:rich_text_publisher:1.1
-
cpe:2.3:a:jenkins:rich_text_publisher:1.2
-
cpe:2.3:a:jenkins:rich_text_publisher:1.3
-
cpe:2.3:a:jenkins:rich_text_publisher:1.4