CVE-2022-34196: XSS
Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34196?
CVE-2022-34196 has a medium severity as it allows for a stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2022-34196?
To fix CVE-2022-34196, upgrade the Jenkins REST List Parameter Plugin to version 1.5.3 or later.
Who is impacted by CVE-2022-34196?
CVE-2022-34196 affects users with Item/Configure permissions in Jenkins environments using the vulnerable plugin version.
What type of vulnerability is CVE-2022-34196?
CVE-2022-34196 is classified as a stored cross-site scripting (XSS) vulnerability.
What versions of the Jenkins REST List Parameter Plugin are affected by CVE-2022-34196?
CVE-2022-34196 affects Jenkins REST List Parameter Plugin versions up to and including 1.5.2.