Stored Cross-Site Scripting Vulnerability in Jenkins Promoted Builds Plugin
CVE-2022-30965
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 17 May 2022
What is CVE-2022-30965?
A stored cross-site scripting vulnerability exists in the Jenkins Promoted Builds (Simple) Plugin versions 1.9 and earlier, where the name and description of Promotion Level parameters are not properly escaped on views that display these parameters. This flaw allows attackers with Item/Configure permissions to inject malicious scripts that can be executed in the context of users accessing the affected views, potentially leading to unauthorized actions or data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Promoted Builds (Simple) Plugin <= 1.9
References
EPSS Score
31% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved