CVE-2022-29046Cross-site Scripting in Project Jenkins Subversion Plugin

Severity
5.4MEDIUMNVD
EPSS
2.3%
top 15.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateJul 20

Description

Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

CVEListV5jenkins_project/jenkins_subversion_pluginunspecified2.15.3
NVDjenkins/subversion2.15.3
NVDapple/macos12.012.5

🔴Vulnerability Details

3
OSV
Stored Cross-site Scripting vulnerability in Jenkins Subversion Plugin2022-04-13
GHSA
Stored Cross-site Scripting vulnerability in Jenkins Subversion Plugin2022-04-13
CVEList
CVE-2022-29046: Jenkins Subversion Plugin 22022-04-12

📋Vendor Advisories

3
Apple
CVE-2022-29046: macOS Monterey 12.52022-07-20
Jenkins
Jenkins Security Advisory 2022-04-122022-04-12
Red Hat
subversion: Stored XSS vulnerabilities in Jenkins subversion plugin2022-04-12
CVE-2022-29046 — Cross-site Scripting | cvebase