CVE Database
/

CVE-2022-45380

Back to search

CVE-2022-45380

Published: Nov 15, 2022

Modified: Apr 30, 2025

PUBLISHED

Description

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

VendorProductVersions

Jenkins project

Jenkins JUnit Plugin

affected
unspecified - <= 1159.v0b_396e1e07dd
unaffected
1143.1145.v81b_b_9579a_019
unaffected
1119.1122.v750e65d31b_db_

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now