CVE-2019-10346Cross-site Scripting in Jenkins Embeddable Build Status

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 51.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 24

Description

A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Jenkins Embeddable Build Status Plugin contains Cross-site Scripting2022-05-24
GHSA
Jenkins Embeddable Build Status Plugin contains Cross-site Scripting2022-05-24
CVEList
CVE-2019-10346: A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 22019-07-11

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-07-112019-07-11
CVE-2019-10346 — Cross-site Scripting in Jenkins | cvebase