← Vulnerability feed

Vulnerability record · CVE-2022-20615 · published 12 January 2022

CVE-2022-20615: Jenkins Matrix Project Plugin stored XSS via unescaped node and label names

Jenkins · Matrix Project

Jenkins Matrix Project Plugin 1.19 and earlier fails to escape HTML metacharacters in node names, label names, and label descriptions. This allows an attacker with Agent/Configure permission to store script that executes in the browser of other Jenkins users who view the affected content. Because the payload persists in Jenkins configuration, it can affect multiple users over time.

5.4 CVSS 3.1 Medium EPSS 82% · top 0.4% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS rates this medium (5.4) and exploitation requires authenticated Agent/Configure permission plus victim interaction, though the high EPSS score warrants prompt patching.

What it is

Jenkins Matrix Project Plugin 1.19 and earlier fails to escape HTML metacharacters in node names, label names, and label descriptions. This allows an attacker with Agent/Configure permission to store script that executes in the browser of other Jenkins users who view the affected content. Because the payload persists in Jenkins configuration, it can affect multiple users over time.

Impact

An attacker can execute arbitrary JavaScript in the context of a victim's Jenkins session, potentially stealing session cookies or performing actions as the victim. The scope change in the CVSS vector indicates the XSS can affect resources beyond the vulnerable component.

Attack surface

The flaw is reachable over the network through the Jenkins web interface. It requires the attacker to hold Agent/Configure permission, and successful exploitation requires a victim to view the crafted node, label, or label description, so user interaction is needed.

Exploitation

The CVE is not listed in CISA KEV, and no ransomware use is documented. EPSS is high at 0.81842 (99.63rd percentile), but the references only include vendor advisories and a patch notice, with no public exploit code or in-the-wild reporting.

What to do

  • Upgrade Jenkins Matrix Project Plugin to a version later than 1.19 as directed by the Jenkins security advisory.
  • Apply the Oracle CPU April 2022 patch if the plugin is bundled in Oracle Communications Cloud Native Core Automated Test Suite.
  • Restrict Agent/Configure permission to trusted users only.
  • Review and remove any untrusted node names, label names, or label descriptions that contain HTML metacharacters.

Detection

  • Search Jenkins node, label, and label description configuration for HTML metacharacters such as <, >, and &.
  • Audit Jenkins access logs for requests that create or modify nodes, labels, or label descriptions by users with Agent/Configure permission.
  • Monitor for unexpected script execution or outbound requests from Jenkins user sessions after viewing node or label pages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-20615 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed9.9CVE-2019-1003031Jenkins matrix project vulnerabilityA sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java tha…EPSS 3.4%9.8CVE-2021-29921Python vulnerabilityIn Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) all…EPSS 6.9%8.8CVE-2021-39139Xstream unrestricted file upload vulnerabilityXStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…EPSS 4.5%8.8CVE-2019-10384Jenkins cross-site request forgery vulnerabilityJenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-20615), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.