CVE-2022-29039

Severity
5.4MEDIUM
EPSS
10.0%
top 6.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateApr 13

Description

Jenkins Gerrit Trigger Plugin 2.35.2 and earlier does not escape the name and description of Base64 Encoded String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Stored Cross-site Scripting vulnerability in Jenkins Gerrit Trigger Plugin2022-04-13
OSV
Stored Cross-site Scripting vulnerability in Jenkins Gerrit Trigger Plugin2022-04-13
CVEList
CVE-2022-29039: Jenkins Gerrit Trigger Plugin 22022-04-12

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-04-122022-04-12