CVE-2022-30970

MEDIUM

Jenkins Autocomplete Parameter Plugin <1.1 - XSS

Title source: llm
STIX 2.1

Description

Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0999
EPSS Percentile 93.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
jenkins/autocomplete_parameter < 1.1
org.jenkins-ci.plugins/autocomplete-parameter 0Maven
Published May 17, 2022
Tracked Since Feb 18, 2026