CVE Published: 12/04/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Node and Label parameter Plugin Status : PUBLISHED
CVE-2022-29044 Description
Jenkins Node and Label parameter Plugin 1.10.3 and earlier does not escape the name and description of Node and Label parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.