CVE-2019-10346

A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
References
Link Resource
http://www.openwall.com/lists/oss-security/2019/07/11/4 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/109156 Broken Link Third Party Advisory VDB Entry
https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1419 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:embeddable_build_status:*:*:*:*:*:jenkins:*:*

History

30 Jan 2023, 18:40

Type Values Removed Values Added
References (BID) http://www.securityfocus.com/bid/109156 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/109156 - Broken Link, Third Party Advisory, VDB Entry

Information

Published : 2019-07-11 14:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-10346

Mitre link : CVE-2019-10346

CVE.ORG link : CVE-2019-10346


JSON object : View

Products Affected

jenkins

  • embeddable_build_status
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')