CVE-2022-29036
published 2022-04-12CVE-2022-29036: Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name…
PriorityP342medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
78.55%
99.5th percentile
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | build_step_plugin | — | — |
| jenkins | coordinator_plugin | — | — |
| jenkins | credentials | < 2.6.1.1 | 2.6.1.1 |
| jenkins | credentials | >= 1055.v1346ba467ba1 < 1074.1076.v39c30cecb_0e2 | 1074.1076.v39c30cecb_0e2 |
| jenkins | credentials | >= 1105.vb_4e24a_c78b_81 < 1112.vc87b_7a_3597f6 | 1112.vc87b_7a_3597f6 |
| jenkins | credentials_plugin | — | — |
| jenkins | cvs_plugin | — | — |
| jenkins | deprecated_groovy_libraries_plugin | — | — |
| jenkins | extended_choice_parameter_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | git_parameter_plugin | — | — |
| jenkins | google_compute_engine_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | jira_plugin | — | — |
| jenkins | job_dsl_plugin | — | — |
| jenkins | job_generator_plugin | — | — |
| jenkins | mask_passwords_plugin | — | — |
| jenkins | maven_release_plugin | — | — |
| jenkins | node_and_label_parameter_plugin | — | — |
| jenkins | promotion_names_in_promoted_builds_plugin | — | — |
| jenkins | publish_over_ftp_plugin | — | — |
| jenkins | rebuilder_plugin | — | — |
| jenkins | release_plugin | — | — |
| jenkins | show_build_parameters_plugin | — | — |
| jenkins | subversion_plugin | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for unescaped name/description fields in Credentials parameters on Jenkins views — a stored XSS payload injected there by a user with Item/Configure permission indicates exploitation of this vulnerability.
- ·Vulnerable versions are Jenkins Credentials Plugin 1111.v35a_307992395 and earlier; fixed versions are 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1 — ensure the installed plugin version is one of these patched releases. ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Credentials Plugin up to 1111.v35a_307992395 on Jenkins name/description cross site scripting (Nessus ID 312087)
vuldb·2026-05-05·CVSS 5.4
CVE-2022-29036 [MEDIUM] Credentials Plugin up to 1111.v35a_307992395 on Jenkins name/description cross site scripting (Nessus ID 312087)
A vulnerability classified as problematic has been found in Credentials Plugin up to 1111.v35a_307992395 on Jenkins. This issue affects some unknown processing. This manipulation of the argument name/description causes cross site scripting.
This vulnerability is registered as CVE-2022-29036. Remote exploitation of the attack is possible. No exploit is available.
GHSA
Cross-site Scripting in Jenkins Credentials Plugin
ghsa·2022-04-13
CVE-2022-29036 [MEDIUM] CWE-79 Cross-site Scripting in Jenkins Credentials Plugin
Cross-site Scripting in Jenkins Credentials Plugin
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
OSV
Cross-site Scripting in Jenkins Credentials Plugin
osv·2022-04-13
CVE-2022-29036 [MEDIUM] Cross-site Scripting in Jenkins Credentials Plugin
Cross-site Scripting in Jenkins Credentials Plugin
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Red Hat
credentials: Stored XSS vulnerabilities in jenkins plugin
vendor_redhat·2022-04-12·CVSS 5.4
CVE-2022-29036 [MEDIUM] CWE-79 credentials: Stored XSS vulnerabilities in jenkins plugin
credentials: Stored XSS vulnerabilities in jenkins plugin
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
A flaw was found in the Jenkins credentials plugin. The Jenkins credentials plugin does not escape the name and description of Credentials parameters on views displaying parameters. This issue results in a stored Cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Jenkins
Jenkins Security Advisory 2022-04-12
vendor_jenkins·2022-04-12·CVSS 5.4
CVE-2017-2601 [MEDIUM] Jenkins Security Advisory 2022-04-12
Title: Jenkins Security Advisory 2022-04-12
Jenkins Security Advisory 2022-04-12
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Credentials
Plugin
CVS
Plugin
Extended Choice Parameter
Plugin
Gerrit Trigger
Plugin
Git Parameter
Plugin
Google Compute Engine
Plugin
Jira
Plugin
Job Generator
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-12
Published