PT-2022-18301 · Jenkins · Jenkins Environment Dashboard Plugin+1

Justin Philip

·

Published

2022-03-15

·

Updated

2023-12-22

·

CVE-2022-27213

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Environment Dashboard Plugin versions 1.1.10 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. It occurs because the Environment order and the Component order configuration values in the views are not properly escaped. This vulnerability can be exploited by attackers who have View/Configure permission.
Recommendations For Jenkins Environment Dashboard Plugin versions 1.1.10 and earlier, update to a version later than 1.1.10 to resolve the issue. As a temporary workaround, consider restricting access to the views that contain the Environment order and the Component order configuration values to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-27213
GHSA-35H9-H439-VVMR

Affected Products

Jenkins
Jenkins Environment Dashboard Plugin