Stored Cross-Site Scripting Vulnerability in Jenkins Jira Plugin
CVE-2022-29041
What is CVE-2022-29041?
The Jira Plugin for Jenkins, versions 3.7 and earlier (excluding version 3.6.1), contains a vulnerability that allows attackers with Item/Configure permissions to exploit stored cross-site scripting (XSS). This occurs due to inadequate escaping of the name and description parameters related to Jira Issues and Releases, affecting views that display these parameters. Successful exploitation can lead to unauthorized access and potential manipulation of user sessions, making it critical for users to update their plugins to the latest secure version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Jira Plugin <= 3.7
Jenkins Jira Plugin 3.6.1
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved