CVE-2022-34176
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 78%
probabilidad de explotación
78%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Afectado
1 producto (2 componentes)
Red Hat OpenShift Container Platform 3.11
no_fix_planned: Will not fix
Corregido
3 productos (6 componentes)
Red Hat OpenShift Container Platform 4.10 · Red Hat OpenShift Container Platform 4.8 · Red Hat OpenShift Container Platform 4.9
No afectado
3 productos (49 componentes) — porque el código vulnerable no está presente en el producto
Red Hat OpenShift Container Platform 4.10 · Red Hat OpenShift Container Platform 4.9 · Red Hat OpenShift Container Platform 4.8
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
Productos afectados
Jenkins project · Jenkins JUnit Plugin