Lucene search

K
cveJenkinsCVE-2022-41240
HistorySep 21, 2022 - 4:15 p.m.

CVE-2022-41240

2022-09-2116:15:10
CWE-79
jenkins
web.nvd.nist.gov
215
2
cve-2022-41240
jenkins
walti plugin
xss
api
security vulnerability

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.8%

Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.

Affected configurations

Nvd
Node
jenkinswaltiRange≀1.0.1jenkins
VendorProductVersionCPE
jenkinswalti*cpe:2.3:a:jenkins:walti:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins Walti Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.0.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.0.1",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

22.8%

Related for CVE-2022-41240