CVE-2019-10383
published 2019-08-28CVE-2019-10383: A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to…
medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | ibm_appscan_plugin | — | — |
| jenkins | jenkins | <= 2.176.2 | — |
| jenkins | jenkins | <= 2.191 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | splunk_plugin | — | — |
| jenkins | strict_crumb_issuer_plugin | — | — |
| jenkins_project | jenkins | — | — |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |