Lucene search

K
cveJenkinsCVE-2022-41239
HistorySep 21, 2022 - 4:15 p.m.

CVE-2022-41239

2022-09-2116:15:10
CWE-79
jenkins
web.nvd.nist.gov
52
2
cve-2022-41239
jenkins
dotci plugin
github
xss
vulnerability
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.8%

Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.

Affected configurations

Nvd
Node
jenkinsdotciRange2.40.00jenkins
VendorProductVersionCPE
jenkinsdotci*cpe:2.3:a:jenkins:dotci:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins DotCi Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "2.40.00",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 2.40.00",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.8%

Related for CVE-2022-41239