Description
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6736 | Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti. |
Github GHSA |
GHSA-7qpm-vmwv-hq7h | Stored XSS vulnerability in Jenkins Walti plugin |
References
History
Wed, 28 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-28T14:52:17.300Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-41240
Updated: 2024-08-03T12:35:49.691Z
Status : Modified
Published: 2022-09-21T16:15:10.790
Modified: 2025-05-28T15:15:22.627
Link: CVE-2022-41240
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA