CVE-2022-29036
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 79.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 78.97% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jenkins/credentials
- Source
- jenkinsci-cert@googlegroups.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.