CVE-2022-25203: XSS
Published Feb 15, 2022
·Updated
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.
Affected Software
2 affected components
maven/com.sonymobile.jenkins.plugins.teamviews:team-views<=0.9.0
Jenkins Team Views Jenkins<=0.9.0
Event History
Feb 15, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Feb 16, 2022
Advisory Published
12:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-25203?
CVE-2022-25203 is classified as a stored cross-site scripting (XSS) vulnerability with a medium severity risk.
2
Who is affected by CVE-2022-25203?
CVE-2022-25203 affects Jenkins Team Views Plugin versions 0.9.0 and earlier.
3
How do I fix CVE-2022-25203?
To fix CVE-2022-25203, upgrade the Jenkins Team Views Plugin to a version later than 0.9.0.
4
What is the nature of the vulnerability in CVE-2022-25203?
CVE-2022-25203 allows attackers with Overall/Read permission to execute arbitrary script code via unescaped team names.
5
What permissions do attackers need to exploit CVE-2022-25203?
Attackers need Overall/Read permissions to exploit the vulnerability identified in CVE-2022-25203.