VYPR
High severityNVD Advisory· Published Mar 29, 2022· Updated Aug 3, 2024

CVE-2022-28149

CVE-2022-28149

Description

Stored XSS in Jenkins Job and Node Ownership Plugin allows attackers with Item/Configure permission to execute arbitrary JavaScript.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Jenkins Job and Node Ownership Plugin allows attackers with Item/Configure permission to execute arbitrary JavaScript.

Vulnerability

Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in a stored cross-site scripting (XSS) vulnerability [1][2][3]. This affects all versions up to and including 0.13.0.

Exploitation

An attacker with Item/Configure permission can set a secondary owner name to a malicious JavaScript payload. When the owner name is displayed in the Jenkins UI, the script executes in the context of the victim's browser [1][2][3].

Impact

Successful exploitation allows arbitrary JavaScript execution in the Jenkins interface. This can lead to information disclosure, session hijacking, or actions performed on behalf of the victim user [1].

Mitigation

As of the Jenkins Security Advisory 2022-03-29, this vulnerability remains unpatched [2]. No fixed version is available. Administrators should consider removing the plugin or restricting Item/Configure permissions to trusted users only. Monitor the plugin's GitHub repository for future updates [4].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.synopsys.jenkinsci:ownershipMaven
<= 0.13.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1