CVE-2022-29040Cross-site Scripting in Project Jenkins GIT Parameter Plugin

Severity
5.4MEDIUMNVD
EPSS
10.0%
top 6.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateApr 13

Description

Jenkins Git Parameter Plugin 0.9.15 and earlier does not escape the name and description of Git parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5jenkins_project/jenkins_git_parameter_pluginunspecified0.9.15

🔴Vulnerability Details

3
OSV
Stored XSS vulnerability in Jenkins Git Parameter Plugin2022-04-13
GHSA
Stored XSS vulnerability in Jenkins Git Parameter Plugin2022-04-13
CVEList
CVE-2022-29040: Jenkins Git Parameter Plugin 02022-04-12

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-04-122022-04-12
CVE-2022-29040 — Cross-site Scripting | cvebase