CVE-2022-28149
Description
Stored XSS in Jenkins Job and Node Ownership Plugin allows attackers with Item/Configure permission to execute arbitrary JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Jenkins Job and Node Ownership Plugin allows attackers with Item/Configure permission to execute arbitrary JavaScript.
Vulnerability
Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in a stored cross-site scripting (XSS) vulnerability [1][2][3]. This affects all versions up to and including 0.13.0.
Exploitation
An attacker with Item/Configure permission can set a secondary owner name to a malicious JavaScript payload. When the owner name is displayed in the Jenkins UI, the script executes in the context of the victim's browser [1][2][3].
Impact
Successful exploitation allows arbitrary JavaScript execution in the Jenkins interface. This can lead to information disclosure, session hijacking, or actions performed on behalf of the victim user [1].
Mitigation
As of the Jenkins Security Advisory 2022-03-29, this vulnerability remains unpatched [2]. No fixed version is available. Administrators should consider removing the plugin or restricting Item/Configure permissions to trusted users only. Monitor the plugin's GitHub repository for future updates [4].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.synopsys.jenkinsci:ownershipMaven | <= 0.13.0 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-x63v-prhc-xx6fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-28149ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/03/29/1ghsamailing-listx_refsource_MLISTWEB
- www.jenkins.io/security/advisory/2022-03-29/ghsax_refsource_CONFIRMWEB
News mentions
1- Jenkins Security Advisory 2022-03-29Jenkins Security Advisories · Mar 29, 2022