Stored Cross-Site Scripting Vulnerability in Jenkins Generic Webhook Trigger Plugin
CVE-2022-25185

5.4MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
15 February 2022

What is CVE-2022-25185?

The Jenkins Generic Webhook Trigger Plugin versions up to 1.81 does not properly escape the build cause when a webhook is triggered. This oversight introduces a stored cross-site scripting (XSS) vulnerability that can be exploited by attackers who have Item/Configure permissions. Success in exploiting this flaw allows malicious scripts to be executed in the context of users accessing the affected Jenkins instance, potentially compromising sensitive data and user interactions.

Affected Version(s)

Jenkins Generic Webhook Trigger Plugin <= 1.81

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.