Description
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4m42-8qfq-h3q9 | Cross-site Scripting in Jenkins Rundeck Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T07:03:39.842Z
Reserved: 2022-05-16T00:00:00.000Z
Link: CVE-2022-30956
No data.
Status : Modified
Published: 2022-05-17T15:15:09.687
Modified: 2024-11-21T07:03:37.603
Link: CVE-2022-30956
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA