cbcvebase.
CVE-2022-30956
published 2022-05-17

CVE-2022-30956: Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS)…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.

Affected

22 ranges
VendorProductVersion rangeFixed in
jenkinsapplication_detector_plugin
jenkinsautocomplete_parameter_plugin
jenkinsblue_ocean_plugin
jenkinsgit_plugin
jenkinsgitlab_plugin
jenkinsglobal_variable_string_parameter_plugin
jenkinsgroovy_plugin
jenkinshttp_requests_in_script_security_plugin
jenkinsjdk_parameter_plugin
jenkinsjenkins_core
jenkinsmercurial_plugin
jenkinsmultiselect_parameter_plugin
jenkinsrandom_string_parameter_plugin
jenkinsrepo_plugin
jenkinsrundeck<= 3.6.10
jenkinsrundeck_plugin
jenkinsscript_security_plugin
jenkinsselection_tasks_plugin
jenkinsssh_plugin
jenkinsstorable_configs_plugin
jenkinswhile_credentials_plugin
jenkins_projectjenkins_rundeck_pluginunspecified – 3.6.10