CVE-2022-46686

CVSS V2 None CVSS V3 None
Description
Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set or change these values.
Overview
  • CVE ID
  • CVE-2022-46686
  • Assigner
  • jenkinsci-cert@googlegroups.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-12T09:15:13
  • Last Modified Date
  • 2022-12-12T19:14:32
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:jenkins:custom_build_properties:*:*:*:*:*:jenkins:*:* 1 OR 2.79.vc095ccc85094
History
Created Old Value New Value Data Type Notes
2022-12-12 10:15:00 Added to TrackCVE
2022-12-12 12:24:35 2022-12-12T09:15:13.137 2022-12-12T09:15:13 CVE Published Date updated
2022-12-12 12:24:35 2022-12-12T11:26:32 CVE Modified Date updated
2022-12-12 12:24:35 Received Awaiting Analysis Vulnerability Status updated
2022-12-12 17:15:24 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-12 19:15:45 2022-12-12T19:14:32 CVE Modified Date updated
2022-12-12 19:15:45 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-12 19:15:45 CWE-79 Weakness Enumeration new
2022-12-12 19:15:46 CPE Information updated