Vulnerability record · CVE-2022-29036 · published 12 April 2022
CVE-2022-29036: Jenkins Credentials Plugin stored XSS via unescaped parameter names
Jenkins · Credentials
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier (excluding several patched releases) fails to escape the name and description of Credentials parameters on views that display parameters. This allows stored cross-site scripting, and the flaw matters because injected script persists in Jenkins views and executes in the browsers of users who view them.
Description
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw requires Item/Configure permission and victim interaction, but stored XSS in Jenkins can lead to session compromise and EPSS predicts high exploitation likelihood.
What it is
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier (excluding several patched releases) fails to escape the name and description of Credentials parameters on views that display parameters. This allows stored cross-site scripting, and the flaw matters because injected script persists in Jenkins views and executes in the browsers of users who view them.
Impact
An attacker with Item/Configure permission can store script that runs in the context of other users' sessions when they view the affected parameter views, enabling session or credential theft and actions as the victim. The CVSS vector limits scope to low confidentiality and integrity impact.
Attack surface
Reached over the network through Jenkins views that display Credentials parameters; the attacker needs Item/Configure permission and the victim must view the crafted view, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at 0.78965 (99.575th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade the Jenkins Credentials Plugin to a release after 1111.v35a_307992395, or to one of the fixed versions 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, or 2.6.1.1.
- Restrict Item/Configure permission to trusted users only, since the flaw requires that permission to exploit.
- Review and remove any unexpected or suspicious Credentials parameter names and descriptions in Jenkins items.
- Apply the Jenkins security advisory guidance and keep Jenkins core and plugins current.
Detection
- Search Jenkins item configurations for Credentials parameter names or descriptions containing HTML or script tags.
- Monitor Jenkins audit logs for Item/Configure changes made by unexpected users.
- Inspect web access logs for requests to parameter views preceded by suspicious configuration changes.
- Review browser or proxy alerts for script execution originating from Jenkins parameter pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2617 | Vendor Advisory |
| https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2617 | Vendor Advisory |
Track CVE-2022-29036 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29036), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.