cbcvebase.
CVE-2019-10432
published 2019-10-01

CVE-2019-10432: Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsdingtalk_plugin
jenkinshtml_publisher<= 1.20
jenkinshtml_publisher_plugin
jenkinsldap_email_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security_plugin
jenkinssourcegear_vault_plugin
jenkins_projectjenkins_html_publisher_plugin