Description
Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set or change these values.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7515 | Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set or change these values. |
Github GHSA |
GHSA-5g2c-j6v9-vf94 | Jenkins Custom Build Properties Plugin vulnerable to Cross-site Scripting |
References
History
Wed, 23 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-04-23T15:43:14.301Z
Reserved: 2022-12-06T00:00:00.000Z
Link: CVE-2022-46686
Updated: 2024-08-03T14:39:38.677Z
Status : Modified
Published: 2022-12-12T09:15:13.137
Modified: 2025-04-23T16:15:28.567
Link: CVE-2022-46686
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA