Vulnerability record · CVE-2022-34777 · published 30 June 2022
CVE-2022-34777: Jenkins GitLab Plugin stored XSS in webhook build descriptions
Jenkins · Gitlab
Jenkins GitLab Plugin 1.5.34 and earlier fails to escape multiple fields inserted into the description of webhook-triggered builds, creating a stored cross-site scripting flaw. Because the injected content persists in build descriptions, it can execute in the browser of any user who views the affected build, making it a persistent rather than one-shot issue.
Description
Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw requires authenticated Item/Configure permission and victim interaction, but its stored nature and very high EPSS score warrant prompt patching.
What it is
Jenkins GitLab Plugin 1.5.34 and earlier fails to escape multiple fields inserted into the description of webhook-triggered builds, creating a stored cross-site scripting flaw. Because the injected content persists in build descriptions, it can execute in the browser of any user who views the affected build, making it a persistent rather than one-shot issue.
Impact
An attacker with Item/Configure permission can store script content that runs in the context of other users' sessions when they view the build description, enabling session theft or actions performed as the victim. The scope change in the CVSS vector indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through webhook-triggered build descriptions in the Jenkins UI; the attacker needs Item/Configure permission and a victim must view the crafted build description, so both authentication and user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high at roughly 0.73 (99th percentile), suggesting elevated likelihood of attempted exploitation despite the absence of confirmed in-the-wild activity.
What to do
- Upgrade Jenkins GitLab Plugin to a version later than 1.5.34 that escapes the affected webhook build description fields.
- If immediate upgrade is not possible, restrict Item/Configure permission to trusted users only.
- Review and remove any suspicious existing webhook-triggered build descriptions that may contain injected markup.
- Apply output encoding or sanitization for build description fields as a compensating control where feasible.
Detection
- Search Jenkins build descriptions for HTML or script tags introduced via GitLab webhook-triggered builds.
- Monitor Jenkins audit logs for Item/Configure permission grants or changes by unexpected accounts.
- Alert on webhook payloads containing script or event-handler patterns reaching the GitLab plugin endpoint.
- Review browser or proxy logs for script execution originating from Jenkins build description pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2316 | Vendor Advisory |
| https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2316 | Vendor Advisory |
Track CVE-2022-34777 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-34777), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.