CVE-2022-29038: XSS
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a86c and earlier does not escape the name and description of Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29038?
CVE-2022-29038 has been classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2022-29038?
To fix CVE-2022-29038, upgrade to Jenkins Extended Choice Parameter Plugin version 347 or later.
What type of vulnerability is CVE-2022-29038?
CVE-2022-29038 is classified as a stored cross-site scripting (XSS) vulnerability that affects views displaying Extended Choice parameters.
Who is affected by CVE-2022-29038?
All users of Jenkins Extended Choice Parameter Plugin version 346.vd87693c5a_86c and earlier with Item/Configure permission are affected by CVE-2022-29038.
Is CVE-2022-29038 exploitable remotely?
Yes, CVE-2022-29038 is exploitable remotely by attackers who have the required permissions in Jenkins.