← Vulnerability feed

Vulnerability record · CVE-2022-29036 · published 12 April 2022

CVE-2022-29036: Jenkins Credentials Plugin stored XSS via unescaped parameter names

Jenkins · Credentials

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier (excluding several patched releases) fails to escape the name and description of Credentials parameters on views that display parameters. This allows stored cross-site scripting, and the flaw matters because injected script persists in Jenkins views and executes in the browsers of users who view them.

5.4 CVSS 3.1 Medium EPSS 79% · top 0.4% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw requires Item/Configure permission and victim interaction, but stored XSS in Jenkins can lead to session compromise and EPSS predicts high exploitation likelihood.

What it is

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier (excluding several patched releases) fails to escape the name and description of Credentials parameters on views that display parameters. This allows stored cross-site scripting, and the flaw matters because injected script persists in Jenkins views and executes in the browsers of users who view them.

Impact

An attacker with Item/Configure permission can store script that runs in the context of other users' sessions when they view the affected parameter views, enabling session or credential theft and actions as the victim. The CVSS vector limits scope to low confidentiality and integrity impact.

Attack surface

Reached over the network through Jenkins views that display Credentials parameters; the attacker needs Item/Configure permission and the victim must view the crafted view, so user interaction is required.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at 0.78965 (99.575th percentile), indicating elevated predicted exploitation activity.

What to do

  • Upgrade the Jenkins Credentials Plugin to a release after 1111.v35a_307992395, or to one of the fixed versions 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, or 2.6.1.1.
  • Restrict Item/Configure permission to trusted users only, since the flaw requires that permission to exploit.
  • Review and remove any unexpected or suspicious Credentials parameter names and descriptions in Jenkins items.
  • Apply the Jenkins security advisory guidance and keep Jenkins core and plugins current.

Detection

  • Search Jenkins item configurations for Credentials parameter names or descriptions containing HTML or script tags.
  • Monitor Jenkins audit logs for Item/Configure changes made by unexpected users.
  • Inspect web access logs for requests to parameter views preceded by suspicious configuration changes.
  • Review browser or proxy alerts for script execution originating from Jenkins parameter pages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29036 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2024-47805Jenkins credentials insufficiently protected credentials vulnerabilityJenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using…EPSS 0.59%6.1CVE-2021-21648Jenkins credentials cross-site scripting vulnerabilityJenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site …EPSS 11%4.3CVE-2019-10320Jenkins credentials vulnerabilityJenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the …EPSS 0.95%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2022-29036), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.