Stored XSS Vulnerability in Jenkins Autocomplete Parameter Plugin
CVE-2022-30970
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 17 May 2022
What is CVE-2022-30970?
The Autocomplete Parameter Plugin for Jenkins has a vulnerability that allows attackers to exploit stored cross-site scripting (XSS) in certain parameter names. This issue arises from unsafe references to Dropdown Autocomplete and Auto Complete String parameters within the plugin's JavaScript embedded in view definitions. Attackers with Item/Configure permissions can trigger this vulnerability, posing significant security risks to Jenkins instances using affected versions of the plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Autocomplete Parameter Plugin <= 1.1
References
EPSS Score
31% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved