CVE-2022-25191: XSS
Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25191?
CVE-2022-25191 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-25191?
To fix CVE-2022-25191, update the Jenkins Agent Server Parameter Plugin to version 1.1 or later.
Who is affected by CVE-2022-25191?
CVE-2022-25191 affects users of Jenkins Agent Server Parameter Plugin version 1.0 and earlier with Item/Configure permission.
What type of vulnerability is CVE-2022-25191?
CVE-2022-25191 is a stored cross-site scripting (XSS) vulnerability that can be exploited by attackers.
What could be the consequences of exploiting CVE-2022-25191?
Exploiting CVE-2022-25191 could allow an attacker to execute arbitrary scripts in the context of a victim user’s session.