Cross-Site Scripting Vulnerability in Jenkins Credentials Plugin
CVE-2022-29036
What is CVE-2022-29036?
The Jenkins Credentials Plugin prior to version 1111.v35a_307992395 fails to properly escape the names and descriptions of Credential parameters in certain views. This oversight allows attackers with Item/Configure permissions to exploit the vulnerability, potentially leading to stored cross-site scripting attacks. By utilizing crafted credentials, an attacker could execute arbitrary scripts in the context of users accessing the affected views, increasing the risk of further security compromises.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Credentials Plugin <= 1111.v35a_307992395
Jenkins Credentials Plugin 2.6.1.1
Jenkins Credentials Plugin 1074.1076.v39c30cecb_0e2
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved