{"id":"GHSA-jmxr-w2jc-qp7w","summary":"Promotion names in Jenkins promoted builds Plugin are not validated when using Job DSL","details":"Jenkins promoted builds Plugin provides dedicated support for defining promotions using [Job DSL Plugin](https://plugins.jenkins.io/job-dsl).\n\npromoted builds Plugin 873.v6149db_d64130 and earlier does not validate the names of promotions defined in Job DSL. This allows attackers with Job/Configure permission to create a promotion with an unsafe name. As a result, the promotion name could be used for cross-site scripting (XSS) or to replace other `config.xml` files.\n\npromoted builds Plugin 876.v99d29788b_36b_ and 3.10.1 validates the name of promotions.","aliases":["CVE-2022-29049"],"modified":"2024-02-16T08:15:40.160330Z","published":"2022-04-13T00:00:16Z","database_specific":{"cwe_ids":["CWE-20","CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-04-22T21:07:53Z","nvd_published_at":"2022-04-12T20:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29049"},{"type":"WEB","url":"https://github.com/jenkinsci/promoted-builds-plugin/commit/d6fd95688ae2052bf9ac7158bc2579c755167fe0"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/promoted-builds-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2655"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:promoted-builds","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/promoted-builds"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.1"}]}],"versions":["2.0","2.1","2.10","2.11","2.12","2.13","2.14","2.15","2.16","2.17","2.18","2.19","2.2","2.20","2.21","2.22","2.22-beta1","2.23","2.23.1","2.24","2.24.1","2.25","2.26","2.27","2.28","2.28.1","2.29","2.29.1","2.3","2.3.1","2.30","2.31","2.31.1","2.4","2.5","2.6","2.6.1","2.6.2","2.7","2.8","2.9","3.0","3.1","3.10","3.2","3.3","3.4","3.5","3.5.1","3.6","3.7","3.9","3.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-jmxr-w2jc-qp7w/GHSA-jmxr-w2jc-qp7w.json"}},{"package":{"name":"org.jenkins-ci.plugins:promoted-builds","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/promoted-builds"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.11"},{"fixed":"876.v99d29788b"}]}],"versions":["3.11","867.v7c3a_b_83a_eb_79","873.v6149db_d64130"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-jmxr-w2jc-qp7w/GHSA-jmxr-w2jc-qp7w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}