Medium severity5.4NVD Advisory· Published Oct 19, 2022· Updated Jun 17, 2026
CVE-2022-43409
CVE-2022-43409
Description
Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-supportMaven | < 839.v35e2736cfd5c | 839.v35e2736cfd5c |
Affected products
3- cpe:2.3:a:jenkins:pipeline\:_supporting_apis:*:*:*:*:*:jenkins:*:*Range: <=838.va_3a_087b_4055b
- Range: unspecified
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2022/10/19/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-64r9-x74q-wxmhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-43409ghsaADVISORY
- www.jenkins.io/security/advisory/2022-10-19/nvdVendor AdvisoryWEB
- github.com/jenkinsci/workflow-support-plugin/commit/35e2736cfd5c56799eece176328906d92b6a0dd1ghsaWEB
News mentions
0No linked articles in our index yet.