Back to search
CVE-2022-45380
Published: Nov 15, 2022
Modified: Apr 30, 2025
PUBLISHED
Description
Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
| Vendor | Product | Versions |
|---|---|---|
Jenkins project | Jenkins JUnit Plugin | affected unspecified - <= 1159.v0b_396e1e07ddunaffected 1143.1145.v81b_b_9579a_019unaffected 1119.1122.v750e65d31b_db_ |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now