CVE-2019-1003050

MEDIUM

Jenkins < 2.164.2 - Stored Cross-Site Scripting via Job URL in f:validateButton

Title source: llm
STIX 2.1

Description

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

References (4)

Core 4
Core References
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107889
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2019:1605
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 5.4
EPSS 0.0093
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (5)
jenkins/jenkins < 2.164.1
jenkins/jenkins < 2.171
oracle/communications_cloud_native_core_automated_test_suite 1.9.0
org.jenkins-ci.main/jenkins-core 0 - 2.164.2Maven
redhat/openshift_container_platform 3.11
Published Apr 10, 2019
Tracked Since Feb 18, 2026