Stored Cross-Site Scripting Vulnerability in Jenkins Maven Metadata Plugin
CVE-2022-34190
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 23 June 2022
What is CVE-2022-34190?
The Jenkins Maven Metadata Plugin for the Jenkins CI server is vulnerable due to improper escaping of the name and description parameters for List maven artifact versions. This flaw allows attackers with Item/Configure permissions to exploit stored cross-site scripting, leading to potential unauthorized actions on the affected Jenkins instance. Administrators should consider reviewing permissions and updating to the latest version to mitigate risks.
Affected Version(s)
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin <= 2.1