Security Advisory

CVE-2022-34778

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-30 17:45:59
Last updated 2024-11-20 15:46:21
Assigner jenkins
CVSS score not scored
State PUBLISHED

Description

Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results if certain job-level options are set, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or control test results.