cbcvebase.
CVE-2022-29045
published 2022-04-12

CVE-2022-29045: Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsbuild_step_plugin
jenkinscoordinator_plugin
jenkinscredentials_plugin
jenkinscvs_plugin
jenkinsdeprecated_groovy_libraries_plugin
jenkinsextended_choice_parameter_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit_parameter_plugin
jenkinsgoogle_compute_engine_plugin
jenkinsinput_step_plugin
jenkinsjira_plugin
jenkinsjob_dsl_plugin
jenkinsjob_generator_plugin
jenkinsmask_passwords_plugin
jenkinsmaven_release_plugin
jenkinsnode_and_label_parameter_plugin
jenkinspromoted_builds< 3.10.13.10.1
jenkinspromoted_builds>= 867.v7c3a_b_83a_eb_79 < 876.v99d29788b_36b_876.v99d29788b_36b_
jenkinspromotion_names_in_promoted_builds_plugin
jenkinspublish_over_ftp_plugin
jenkinsrebuilder_plugin
jenkinsrelease_plugin
jenkinsshow_build_parameters_plugin
jenkinssubversion_plugin
jenkinsunleash_maven_plugin

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
ghsa5.4MEDIUM
osv5.4MEDIUM