Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-46686


Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set or change these values.


Published

2022-12-12T09:15:13.137

Last Modified

2025-04-23T16:15:28.567

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins custom_build_properties ≤ 2.79.vc095ccc85094 Yes

References