SCA: security update for org.jenkins-ci.plugins:xunit (GHSA-298j-9q4w-6rm4)

critical Tenable Self-Hosted Container Security Plugin ID 408820

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-
specified directory if it doesn't exist, and parsing files inside it as test results, allowing attackers
able to control agent processes to create an arbitrary directory on the Jenkins controller or to obtain
test results from existing files in an attacker-specified directory. (CVE-2022-34181)

See Also

https://github.com/advisories/GHSA-298j-9q4w-6rm4

Plugin Details

Severity: Critical

ID: 408820

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2022-34181

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/24/2022

Vulnerability Publication Date: 6/22/2022

Reference Information

CVE: CVE-2022-34181

cwe: CWE-693