Stored Cross-Site Scripting Vulnerability in Jenkins Custom Checkbox Parameter Plugin
CVE-2022-25189
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 February 2022
What is CVE-2022-25189?
The Custom Checkbox Parameter Plugin for Jenkins versions 1.1 and earlier contains a stored cross-site scripting vulnerability due to the improper handling of parameter names for custom checkbox parameters. This flaw allows attackers with Item/Configure permissions to inject malicious scripts into the application, which could lead to unauthorized actions and exposure of sensitive information. It is essential for users of this plugin to apply patches or updates to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Custom Checkbox Parameter Plugin <= 1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved