CVE-2022-34183: XSS
Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34183?
CVE-2022-34183 is classified as a high severity vulnerability due to its stored cross-site scripting (XSS) impact.
How do I fix CVE-2022-34183?
To fix CVE-2022-34183, update the Jenkins Agent Server Parameter Plugin to version 1.2 or later.
Who can exploit CVE-2022-34183?
CVE-2022-34183 can be exploited by attackers who have Item/Configure permissions within Jenkins.
What are the consequences of CVE-2022-34183?
The consequences of CVE-2022-34183 include potential unauthorized execution of scripts in the context of users viewing parameter configurations.
Is there a temporary workaround for CVE-2022-34183?
A temporary workaround for CVE-2022-34183 is to restrict Item/Configure permissions for users who do not need access.