PT-2022-19375 · Jenkins · Jenkins Credentials Plugin+1

Daniel Beck

+2

·

Published

2022-04-12

·

Updated

2023-11-17

·

CVE-2022-29036

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Credentials Plugin versions 1111.v35a 307992395 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin does not escape the name and description of Credentials parameters on views displaying parameters. Attackers with Item/Configure permission can exploit this.
Recommendations For versions 1111.v35a 307992395 and earlier, update to a version that includes the fix for this issue to prevent exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-29036
GHSA-RVG5-F5FJ-MXVG
RHSA-2022:0871
RHSA-2022:1600
RHSA-2022:2205
RHSA-2022:2280
RHSA-2022:4909
RHSA-2022:4947

Affected Products

Jenkins
Jenkins Credentials Plugin