Vulnerability Details CVE-2022-46684
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.7%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2022-46684
-
cpe:2.3:a:jenkins:checkmarx:-
-
cpe:2.3:a:jenkins:checkmarx:2020.2.20
-
cpe:2.3:a:jenkins:checkmarx:2020.3.3
-
cpe:2.3:a:jenkins:checkmarx:2020.4.3
-
cpe:2.3:a:jenkins:checkmarx:2020.4.8
-
cpe:2.3:a:jenkins:checkmarx:2021.1.2
-
cpe:2.3:a:jenkins:checkmarx:2021.2.94
-
cpe:2.3:a:jenkins:checkmarx:2021.2.96
-
cpe:2.3:a:jenkins:checkmarx:2021.3.1
-
cpe:2.3:a:jenkins:checkmarx:2021.3.3
-
cpe:2.3:a:jenkins:checkmarx:2021.4.1
-
cpe:2.3:a:jenkins:checkmarx:2021.4.2
-
cpe:2.3:a:jenkins:checkmarx:2021.4.3
-
cpe:2.3:a:jenkins:checkmarx:2022.1.2
-
cpe:2.3:a:jenkins:checkmarx:2022.1.3
-
cpe:2.3:a:jenkins:checkmarx:2022.2.1
-
cpe:2.3:a:jenkins:checkmarx:2022.2.3
-
cpe:2.3:a:jenkins:checkmarx:2022.3.2
-
cpe:2.3:a:jenkins:checkmarx:2022.3.3
-
cpe:2.3:a:jenkins:checkmarx:7.5.0
-
cpe:2.3:a:jenkins:checkmarx:8.0.0
-
cpe:2.3:a:jenkins:checkmarx:8.0.1
-
cpe:2.3:a:jenkins:checkmarx:8.1.0-1
-
cpe:2.3:a:jenkins:checkmarx:8.1.0-2
-
cpe:2.3:a:jenkins:checkmarx:8.2.0
-
cpe:2.3:a:jenkins:checkmarx:8.41.0
-
cpe:2.3:a:jenkins:checkmarx:8.42.0
-
cpe:2.3:a:jenkins:checkmarx:8.5.0
-
cpe:2.3:a:jenkins:checkmarx:8.50.0
-
cpe:2.3:a:jenkins:checkmarx:8.60.0
-
cpe:2.3:a:jenkins:checkmarx:8.60.1
-
cpe:2.3:a:jenkins:checkmarx:8.70.0
-
cpe:2.3:a:jenkins:checkmarx:8.80.0
-
cpe:2.3:a:jenkins:checkmarx:8.80.3
-
cpe:2.3:a:jenkins:checkmarx:8.90.1
-
cpe:2.3:a:jenkins:checkmarx:8.90.3
-
cpe:2.3:a:jenkins:checkmarx:8.90.4