Vulnerabilities > Jenkins > Badge > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2022-23108 Cross-site Scripting vulnerability in Jenkins Badge
Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4