Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29036

Опубликовано: 12 апр. 2022
Источник: redhat
CVSS3: 6.4
EPSS Средний

Описание

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

A flaw was found in the Jenkins credentials plugin. The Jenkins credentials plugin does not escape the name and description of Credentials parameters on views displaying parameters. This issue results in a stored Cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2074847credentials: Stored XSS vulnerabilities in jenkins plugin

EPSS

Процентиль: 94%
0.12722
Средний

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 5.4
github
почти 4 года назад

Cross-site Scripting in Jenkins Credentials Plugin

EPSS

Процентиль: 94%
0.12722
Средний

6.4 Medium

CVSS3