Vulnerability record · CVE-2022-34783 · published 30 June 2022
CVE-2022-34783: Jenkins Plot Plugin stored XSS via unescaped plot descriptions
Jenkins · Plot
Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, creating a stored cross-site scripting flaw. An attacker with Item/Configure permission can persist script that executes in the browsers of users viewing the affected plot.
Description
Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires authenticated Item/Configure permission and victim interaction, but the stored XSS can affect other users and EPSS is very high.
What it is
Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, creating a stored cross-site scripting flaw. An attacker with Item/Configure permission can persist script that executes in the browsers of users viewing the affected plot.
Impact
An attacker can run arbitrary script in a victim's Jenkins session, potentially stealing session data or performing actions as the victim. The scope change in the CVSS vector reflects that the injected script can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through the Jenkins web interface; the attacker needs Item/Configure permission, and exploitation requires a victim to view the crafted plot, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high at 0.814 (99.6th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Jenkins Plot Plugin to a version later than 2.1.10 that escapes plot descriptions.
- Restrict Item/Configure permission to trusted users only.
- Review existing plot descriptions for injected script content and remove anything suspicious.
- Apply Jenkins hardening guidance and keep the core and all plugins current.
Detection
- Search Jenkins job and plot configuration data for script tags or event handler attributes in plot descriptions.
- Monitor Jenkins audit logs for Item/Configure changes made by unexpected accounts.
- Alert on suspicious script execution or outbound requests originating from Jenkins user sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2220 | Vendor Advisory |
| https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2220 | Vendor Advisory |
Track CVE-2022-34783 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-34783), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.