PT-2022-22343 · Jenkins · Jenkins Validating Email Parameter Plugin+1

Published

2022-06-30

·

Updated

2023-12-21

·

CVE-2022-34791

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Validating Email Parameter Plugin versions 1.10 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability. This is due to the plugin not escaping the name and description of its parameter type. Attackers with Item/Configure permission can exploit this. Additionally, the plugin disables security hardening added in Jenkins 2.44 and LTS 2.32.2, which normally protects the "Build With Parameters" and "Parameters" pages from such vulnerabilities by default.
Recommendations For Jenkins Validating Email Parameter Plugin versions 1.10 and earlier, consider disabling the plugin until a patch is available to prevent exploitation of the stored cross-site scripting vulnerability. Restrict access to the "Build With Parameters" and "Parameters" pages to minimize the risk of exploitation. Avoid using the parameter type's name and description fields in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-34791
GHSA-HQMP-VXJ7-5WPQ

Affected Products

Jenkins
Jenkins Validating Email Parameter Plugin