CVE-2022-34170 (https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2781): In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. CVE-2022-34171 (https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2781): In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability. CVE-2022-34172 (https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2781): In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability. CVE-2022-34173 (https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2781): In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. CVE-2022-34174 (https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2566): In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm. CVE-2022-34175 (https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2777): Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view. Please cleanup.
Cleanup done.
Thanks! All done.