CVE-2022-29049: Input Validation
Jenkins promoted builds Plugin 873.v6149dbd64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
Other sources
Jenkins promoted builds Plugin provides dedicated support for defining promotions using Job DSL Plugin.
promoted builds Plugin 873.v6149dbd64130 and earlier does not validate the names of promotions defined in Job DSL. This allows attackers with Job/Configure permission to create a promotion with an unsafe name. As a result, the promotion name could be used for cross-site scripting (XSS) or to replace other config.xml files.
promoted builds Plugin 876.v99d29788b36b and 3.10.1 validates the name of promotions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29049?
CVE-2022-29049 is classified as a medium severity vulnerability due to the potential for attackers to create unsafe promotion names.
How do I fix CVE-2022-29049?
To fix CVE-2022-29049, upgrade the Jenkins promoted builds Plugin to version 3.10.1 or later.
What impact does CVE-2022-29049 have on Jenkins security?
CVE-2022-29049 allows attackers with Job/Configure permission to exploit the vulnerability by creating promotions with unsafe names.
Which versions of Jenkins promoted builds Plugin are affected by CVE-2022-29049?
Versions of Jenkins promoted builds Plugin earlier than 3.10.1, and between 867.v7c3a_b_83a_eb_79 and 876.v99d29788b_36b_ are affected by CVE-2022-29049.
Who is at risk from CVE-2022-29049?
Users of Jenkins with the promoted builds Plugin installed and those with Job/Configure permissions are at risk from CVE-2022-29049.