Stored Cross-Site Scripting Vulnerability in Jenkins Gerrit Trigger Plugin
CVE-2022-29039

5.4MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
12 April 2022

Summary

The Jenkins Gerrit Trigger Plugin versions 2.35.2 and earlier contain a vulnerability that leads to stored cross-site scripting (XSS). The issue arises because the plugin fails to adequately escape the name and description of Base64 Encoded String parameters displayed on views, allowing attackers with Item/Configure permission to inject harmful scripts. An exploit could lead to unauthorized access to user data and manipulation of the application interface.

Affected Version(s)

Jenkins Gerrit Trigger Plugin <= 2.35.2

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.