Cross-Site Scripting Vulnerability in Jenkins Credentials Plugin
CVE-2022-29036

5.4MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
12 April 2022

Summary

The Jenkins Credentials Plugin prior to version 1111.v35a_307992395 fails to properly escape the names and descriptions of Credential parameters in certain views. This oversight allows attackers with Item/Configure permissions to exploit the vulnerability, potentially leading to stored cross-site scripting attacks. By utilizing crafted credentials, an attacker could execute arbitrary scripts in the context of users accessing the affected views, increasing the risk of further security compromises.

Affected Version(s)

Jenkins Credentials Plugin <= 1111.v35a_307992395

Jenkins Credentials Plugin 2.6.1.1

Jenkins Credentials Plugin 1074.1076.v39c30cecb_0e2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.