Stored Cross-Site Scripting Vulnerability in Jenkins Generic Webhook Trigger Plugin
CVE-2022-25185
5.4MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 15 February 2022
Summary
The Jenkins Generic Webhook Trigger Plugin versions up to 1.81 does not properly escape the build cause when a webhook is triggered. This oversight introduces a stored cross-site scripting (XSS) vulnerability that can be exploited by attackers who have Item/Configure permissions. Success in exploiting this flaw allows malicious scripts to be executed in the context of users accessing the affected Jenkins instance, potentially compromising sensitive data and user interactions.
Affected Version(s)
Jenkins Generic Webhook Trigger Plugin <= 1.81
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved