CVE-2022-34187: XSS
Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34187?
The severity of CVE-2022-34187 is rated as high due to the potential for stored cross-site scripting (XSS) attacks.
Who is affected by CVE-2022-34187?
CVE-2022-34187 affects users of Jenkins Filesystem List Parameter Plugin versions 0.0.7 and earlier.
How do I fix CVE-2022-34187?
To fix CVE-2022-34187, upgrade to Jenkins Filesystem List Parameter Plugin version 0.0.8 or later.
What are the consequences of exploiting CVE-2022-34187?
Exploiting CVE-2022-34187 can allow attackers with Item/Configure permission to execute malicious scripts in the context of other users.
Is there a workaround for CVE-2022-34187 if I can't upgrade?
There are no recommended workarounds for CVE-2022-34187; upgrading to a secure version is the best solution.