CVE-2022-29045: Jenkins Promoted Builds
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected products
- Jenkins Promoted Builds: before 3.10.1 (fixed in 3.10.1); from 867.v7c3a_b_83a_eb_79, before 876.v99d29788b_36b_ (fixed in 876.v99d29788b_36b_)
Published 2022-04-12. Last modified 2026-06-17.