CVE-2019-10374

MEDIUM

Jenkins PegDown Formatter Plugin < 1.3 - Stored Cross-Site Scripting via JavaScript Scheme Links

Title source: llm
STIX 2.1

Description

A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/08/07/1

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
jenkins/pegdown_formatter < 1.3
org.jenkins-ci.plugins/pegdown-formatter 0Maven
Published Aug 07, 2019
Tracked Since Feb 18, 2026