Stored Cross-Site Scripting Vulnerability in Jenkins Generic Webhook Trigger Plugin
CVE-2022-25185

5.4MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
15 February 2022

Summary

The Jenkins Generic Webhook Trigger Plugin versions up to 1.81 does not properly escape the build cause when a webhook is triggered. This oversight introduces a stored cross-site scripting (XSS) vulnerability that can be exploited by attackers who have Item/Configure permissions. Success in exploiting this flaw allows malicious scripts to be executed in the context of users accessing the affected Jenkins instance, potentially compromising sensitive data and user interactions.

Affected Version(s)

Jenkins Generic Webhook Trigger Plugin <= 1.81

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.