Stored Cross-Site Scripting Vulnerability in Jenkins Promoted Builds Plugin
CVE-2022-29045
What is CVE-2022-29045?
The Jenkins Promoted Builds Plugin, specifically versions 873.v6149db_d64130 and earlier, is susceptible to a stored cross-site scripting vulnerability. This issue arises due to the plugin's failure to properly escape the name and description fields of Promoted Build parameters on views where these parameters are displayed. As a result, attackers with Item/Configure permissions could exploit this vulnerability to inject malicious scripts, leading to potential risks such as unauthorized access and data manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins promoted builds Plugin <= 873.v6149db_d64130
Jenkins promoted builds Plugin 3.10.1
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved