CVE-2022-41229: XSS
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins NS-ND Integration Performance Publisher Pluginto a version that resolves this vulnerability.Fixed in 4.8.0.134 - Compensating control
Restrict Item/Configure permission so only trusted users can edit Jenkins job configurations, reducing the ability for attackers to exploit the stored XSS vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41229?
CVE-2022-41229 is categorized as a stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2022-41229?
To mitigate CVE-2022-41229, update the Jenkins NS-ND Integration Performance Publisher Plugin to version 4.8.0.135 or later.
What permissions are required to exploit CVE-2022-41229?
An attacker needs Item/Configure permission to exploit CVE-2022-41229.
What versions of the Jenkins NS-ND Integration Performance Publisher Plugin are affected by CVE-2022-41229?
CVE-2022-41229 affects all versions of the Jenkins NS-ND Integration Performance Publisher Plugin up to and including 4.8.0.134.
What impact can CVE-2022-41229 have on Jenkins?
CVE-2022-41229 can lead to stored cross-site scripting (XSS), allowing attackers to execute malicious scripts in users' browsers.