Stored Cross-Site Scripting Vulnerability in Jenkins Maven Metadata Plugin
CVE-2022-34190

5.4MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
23 June 2022

Summary

The Jenkins Maven Metadata Plugin for the Jenkins CI server is vulnerable due to improper escaping of the name and description parameters for List maven artifact versions. This flaw allows attackers with Item/Configure permissions to exploit stored cross-site scripting, leading to potential unauthorized actions on the affected Jenkins instance. Administrators should consider reviewing permissions and updating to the latest version to mitigate risks.

Affected Version(s)

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin <= 2.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.