CVE-2022-25202: XSS
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25202?
CVE-2022-25202 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
Who is affected by CVE-2022-25202?
CVE-2022-25202 affects users of Jenkins Promoted Builds (Simple) Plugin versions 1.9 and earlier.
How do I fix CVE-2022-25202?
To fix CVE-2022-25202, upgrade the Jenkins Promoted Builds (Simple) Plugin to version 1.10 or later.
What is the impact of CVE-2022-25202?
The impact of CVE-2022-25202 is that attackers with Overall/Administer permission can execute malicious scripts in the context of users' browsers.
Is CVE-2022-25202 a common vulnerability?
CVE-2022-25202 represents a common type of vulnerability known as stored XSS, which can be found in web applications with inadequate input sanitization.