CVE Database
/

CVE-2022-43409

Back to search

CVE-2022-43409

Published: Oct 19, 2022

Modified: May 8, 2025

PUBLISHED

Description

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

VendorProductVersions

Jenkins project

Jenkins Pipeline: Supporting APIs Plugin

affected
unspecified - <= 838.va_3a_087b_4055b
unaffected
827.829.v01c0a_3d76c4f

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now