Security Advisory

CVE-2022-34171

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-22 14:40:51
Last updated 2024-08-03 08:16:17
Assigner jenkins
CVSS score not scored
State PUBLISHED

Description

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.