CVE-2019-10346

A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
References
Link Resource
http://www.openwall.com/lists/oss-security/2019/07/11/4 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/109156 Broken Link Third Party Advisory VDB Entry
https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1419 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:embeddable_build_status:*:*:*:*:*:jenkins:*:*

History

No history.

Information

Published : 2019-07-11 14:15

Updated : 2024-02-28 17:08


NVD link : CVE-2019-10346

Mitre link : CVE-2019-10346

CVE.ORG link : CVE-2019-10346


JSON object : View

Products Affected

jenkins

  • embeddable_build_status
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')