CVE Database
/

CVE-2022-30956

Back to search

CVE-2022-30956

Published: May 17, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.

VendorProductVersions

Jenkins project

Jenkins Rundeck Plugin

affected
unspecified - <= 3.6.10

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now