Stored Cross-Site Scripting Vulnerability in Jenkins Gerrit Trigger Plugin
CVE-2022-29039
5.4MEDIUM
Summary
The Jenkins Gerrit Trigger Plugin versions 2.35.2 and earlier contain a vulnerability that leads to stored cross-site scripting (XSS). The issue arises because the plugin fails to adequately escape the name and description of Base64 Encoded String parameters displayed on views, allowing attackers with Item/Configure permission to inject harmful scripts. An exploit could lead to unauthorized access to user data and manipulation of the application interface.
Affected Version(s)
Jenkins Gerrit Trigger Plugin <= 2.35.2
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved