Stored Cross-Site Scripting in Jenkins Selection Tasks Plugin
CVE-2022-30967
What is CVE-2022-30967?
The Jenkins Selection Tasks Plugin prior to version 1.0 is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue arises from the failure to properly escape the name and description of Script Selection task variable parameters when rendered in views that display these parameters. Attackers possessing Item/Configure permissions may exploit this vulnerability to inject malicious scripts into the application's interface, potentially compromising user sessions or executing unauthorized actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Selection tasks Plugin <= 1.0
References
EPSS Score
31% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved