Stored Cross-Site Scripting Vulnerability in Jenkins Rundeck Plugin
CVE-2022-30956

5.4MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
17 May 2022

Summary

The Jenkins Rundeck Plugin versions up to 3.6.10 are susceptible to a stored cross-site scripting vulnerability due to inadequate restrictions on URL schemes within Rundeck webhook submissions. This flaw allows attackers to craft malicious payloads that, when sent via webhooks, can execute arbitrary scripts in the context of the affected user's session, potentially leading to unauthorized data access and other security issues.

Affected Version(s)

Jenkins Rundeck Plugin <= 3.6.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.