{"id":"GHSA-64mj-3p92-589v","summary":"Cross-site Scripting in Jenkins JUnit Plugin","details":"JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results.\n\nThis results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.\n\nJUnit Plugin 1119.1121.vc43d0fc45561 applies the configured markup formatter to descriptions of test results.","aliases":["CVE-2022-34176"],"modified":"2026-08-24T00:35:04.759293962Z","published":"2022-06-24T00:00:31Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-05T22:56:33Z","nvd_published_at":"2022-06-23T17:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34176"},{"type":"WEB","url":"https://github.com/jenkinsci/junit-plugin/commit/c43d0fc455619dd652ec87939ac3d70d6134fea1"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/junit-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2760"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:junit","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/junit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1119.1121.vc43d0fc45561"}]}],"versions":["1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.18","1.19","1.2","1.2-beta-1","1.2-beta-2","1.2-beta-3","1.2-beta-4","1.20","1.21","1.22","1.22-beta-1","1.22.1","1.22.2","1.23","1.24","1.25","1.26","1.26.1","1.27","1.28","1.29","1.3","1.30","1.31","1.32","1.33","1.34","1.35","1.36","1.37","1.38","1.39","1.4","1.41","1.42","1.43","1.44","1.45","1.46","1.47","1.48","1.49","1.5","1.50","1.51","1.52","1.53","1.53.0.1","1.54","1.54.1","1.54.2","1.54.3","1.55","1.56","1.57","1.58","1.59","1.6","1.60","1.61","1.62","1.63","1.7","1.8","1.9","1119.va_a_5e9068da_d7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-64mj-3p92-589v/GHSA-64mj-3p92-589v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}