CVE-2022-29045: XSS
Jenkins promoted builds Plugin 873.v6149dbd64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29045?
CVE-2022-29045 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-29045?
To fix CVE-2022-29045, upgrade to version 3.10.1 or a later version of the Jenkins Promoted Builds plugin.
Who is affected by CVE-2022-29045?
Users of Jenkins Promoted Builds versions 873.v6149db_d64130 and earlier, except 3.10.1, are affected by CVE-2022-29045.
What type of vulnerability is CVE-2022-29045?
CVE-2022-29045 is a stored cross-site scripting (XSS) vulnerability that can be exploited by attackers with Item/Configure permission.
What permissions are required to exploit CVE-2022-29045?
To exploit CVE-2022-29045, an attacker needs Item/Configure permission in Jenkins.