Stored cross-site scripting in JUnit - CVE-2022-45380
Published: November 16, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Red Hat OpenShift Container Platform
cri-o (Red Hat package)
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2022-45380
Red Hat OpenShift Container Platform - addressed in versions 4.9.56, 4.10.51
cri-o (Red Hat package) - addressed in versions 1.23.5-5.rhaos4.10.gitd9dec98.el7, 1.23.5-5.rhaos4.10.gitd9dec98.el8
jenkins (Red Hat package) - update to 2.361.1.1675668150-1.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.9.1675668922-1.el8, 4.10.1675144701-1.el8