CVE-2022-30965: XSS
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30965?
CVE-2022-30965 has a high severity due to its potential for exploitation through stored cross-site scripting (XSS).
How do I fix CVE-2022-30965?
To fix CVE-2022-30965, upgrade the Jenkins Promoted Builds (Simple) Plugin to version 1.10 or later.
Who is affected by CVE-2022-30965?
Users with Item/Configure permission in Jenkins using Promoted Builds Plugin versions 1.9 and earlier are affected by CVE-2022-30965.
What type of vulnerability is CVE-2022-30965?
CVE-2022-30965 is a stored cross-site scripting (XSS) vulnerability.
What version of Jenkins Promoted Builds Plugin is vulnerable in CVE-2022-30965?
Versions of Jenkins Promoted Builds Plugin up to and including 1.9 are vulnerable in CVE-2022-30965.