cbcvebase.
CVE-2022-30965
published 2022-05-17

CVE-2022-30965: Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected

22 ranges
VendorProductVersion rangeFixed in
jenkinsapplication_detector_plugin
jenkinsautocomplete_parameter_plugin
jenkinsblue_ocean_plugin
jenkinsgit_plugin
jenkinsgitlab_plugin
jenkinsglobal_variable_string_parameter_plugin
jenkinsgroovy_plugin
jenkinshttp_requests_in_script_security_plugin
jenkinsjdk_parameter_plugin
jenkinsjenkins_core
jenkinsmercurial_plugin
jenkinsmultiselect_parameter_plugin
jenkinspromoted_builds<= 1.9
jenkinsrandom_string_parameter_plugin
jenkinsrepo_plugin
jenkinsrundeck_plugin
jenkinsscript_security_plugin
jenkinsselection_tasks_plugin
jenkinsssh_plugin
jenkinsstorable_configs_plugin
jenkinswhile_credentials_plugin
jenkins_projectjenkins_promoted_builds_pluginunspecified – 1.9

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
ghsa5.4MEDIUM
osv5.4MEDIUM