cbcvebase.
CVE-2019-10335
published 2019-06-11

CVE-2019-10335: A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the…

PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.13%
62.7th percentile
A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages.

Affected

4 ranges
VendorProductVersion rangeFixed in
jenkinscloudbees_cd_plugin
jenkinselectricflow<= 1.1.6
jenkinstoken_macro_plugin
jenkins_projectjenkins_electricflow_plugin

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.