CVE Published: 22/06/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Embeddable Build Status Plugin Status : PUBLISHED
CVE-2022-34178 Description
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a \'link\' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.