Vulnerability record · CVE-2022-20615 · published 12 January 2022
CVE-2022-20615: Jenkins Matrix Project Plugin stored XSS via unescaped node and label names
Jenkins · Matrix Project
Jenkins Matrix Project Plugin 1.19 and earlier fails to escape HTML metacharacters in node names, label names, and label descriptions. This allows an attacker with Agent/Configure permission to store script that executes in the browser of other Jenkins users who view the affected content. Because the payload persists in Jenkins configuration, it can affect multiple users over time.
Description
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates this medium (5.4) and exploitation requires authenticated Agent/Configure permission plus victim interaction, though the high EPSS score warrants prompt patching.
What it is
Jenkins Matrix Project Plugin 1.19 and earlier fails to escape HTML metacharacters in node names, label names, and label descriptions. This allows an attacker with Agent/Configure permission to store script that executes in the browser of other Jenkins users who view the affected content. Because the payload persists in Jenkins configuration, it can affect multiple users over time.
Impact
An attacker can execute arbitrary JavaScript in the context of a victim's Jenkins session, potentially stealing session cookies or performing actions as the victim. The scope change in the CVSS vector indicates the XSS can affect resources beyond the vulnerable component.
Attack surface
The flaw is reachable over the network through the Jenkins web interface. It requires the attacker to hold Agent/Configure permission, and successful exploitation requires a victim to view the crafted node, label, or label description, so user interaction is needed.
Exploitation
The CVE is not listed in CISA KEV, and no ransomware use is documented. EPSS is high at 0.81842 (99.63rd percentile), but the references only include vendor advisories and a patch notice, with no public exploit code or in-the-wild reporting.
What to do
- Upgrade Jenkins Matrix Project Plugin to a version later than 1.19 as directed by the Jenkins security advisory.
- Apply the Oracle CPU April 2022 patch if the plugin is bundled in Oracle Communications Cloud Native Core Automated Test Suite.
- Restrict Agent/Configure permission to trusted users only.
- Review and remove any untrusted node names, label names, or label descriptions that contain HTML metacharacters.
Detection
- Search Jenkins node, label, and label description configuration for HTML metacharacters such as <, >, and &.
- Audit Jenkins access logs for requests that create or modify nodes, labels, or label descriptions by users with Agent/Configure permission.
- Monitor for unexpected script execution or outbound requests from Jenkins user sessions after viewing node or label pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/01/12/6 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017 | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/12/6 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2017 | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
Track CVE-2022-20615 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-20615), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.