Stored Cross-Site Scripting Vulnerability in Jenkins Mask Passwords Plugin
CVE-2022-29043
What is CVE-2022-29043?
The Jenkins Mask Passwords Plugin, versions 3.0 and earlier, suffers from a stored cross-site scripting (XSS) vulnerability. This flaw arises because it does not properly escape the name and description of Non-Stored Password parameters when displayed in views. Attackers with Item/Configure permission can exploit this vulnerability, potentially leading to unauthorized actions and data exposure. It is essential for users to review and update their installations to combat this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Mask Passwords Plugin <= 3.0
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved