CVE-2022-36905

MEDIUM

Jenkins Maven Metadata Plugin < 2.2 - Stored Cross-Site Scripting via Repository Base URL

Title source: llm
STIX 2.1

Description

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/07/27/1

Scores

CVSS v3 5.4
EPSS 0.0060
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
eu.markov.jenkins.plugin.mvnmeta/maven-metadata-plugin 0Maven
jenkins/maven_metadata < 2.2
Published Jul 27, 2022
Tracked Since Feb 18, 2026