Stored cross-site scripting in Jenkins Subversion Plugin - CVE-2022-29046

 

Stored cross-site scripting in Jenkins Subversion Plugin - CVE-2022-29046

Published: April 13, 2022 / Updated: June 1, 2022


Vulnerability identifier: #VU62304
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2022-29046
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to the affected plugin does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Jenkins Subversion Plugin
cri-tools (Red Hat package)
cri-o (Red Hat package)
conmon (Red Hat package)
ignition (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
jenkins (Red Hat package)
Red Hat OpenShift Container Platform
macOS

How to mitigate CVE-2022-29046

Install updates from vendor's website.

Jenkins Subversion Plugin - update to 2.15.4
cri-tools (Red Hat package) - update to 1.19.0-7.el8
cri-o (Red Hat package) - addressed in versions 1.19.7-2.rhaos4.6.git3c20b65.el7, 1.19.7-2.rhaos4.6.git3c20b65.el8, 1.20.7-4.rhaos4.7.gitb9df556.el7, 1.20.7-4.rhaos4.7.gitb9df556.el8, 1.22.3-5.rhaos4.9.git388405c.el8, 1.22.3-6.rhaos4.9.git388405c.el7
conmon (Red Hat package) - addressed in versions 2.0.21-3.rhaos4.6.el7, 2.0.21-3.rhaos4.6.el8
ignition (Red Hat package) - update to 2.6.0-9.rhaos4.6.git947598e.el8
Red Hat OpenShift Container Platform - addressed in versions 3.11.705, 4.6.59, 4.7.52, 4.9.33
openshift (Red Hat package) - addressed in versions 4.6.0-202205181042.p0.g8203b20.assembly.stream.el7, 4.6.0-202205181042.p0.g8203b20.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.6.1653312933-1.el8, 4.7.1652967082-1.el8, 4.9.1651754460-1.el8
macOS - update to 12.5 21G72
jenkins (Red Hat package) - update to 2.319.3.1651752848-1.el8

External References

Related Security Bulletins