Record summary

CVE-2019-10475 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List1.3 and earlieraffected

org.jenkins-ci.plugins:build-metrics

Browse Maven / org.jenkins-ci.plugins:build-metrics
GitHub AdvisoryThrough 1.3affected

Proofs of concept

2

Catalogued exploits

ExploitDBJenkins build-metrics plugin 1.3 - 'label' Cross-Site ScriptingExploitDB exploitby vescheNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubvesche/CVE-2019-10475Repository PoCby vescheStars: 13Not analyzed5 files

293.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMJenkins build-metrics 1.3 - Cross-Site ScriptingCVSS 6.1

Jenkins build-metrics 1.3 is vulnerable to a reflected cross-site scripting vulnerability that allows attackers to inject arbitrary HTML and JavaScript into the web pages the plugin provides.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser, leading to potential data theft or unauthorized actions.

Remediation

Upgrade to a patched version of the Jenkins build-metrics plugin or apply the necessary fixes provided by the vendor.

WeaknessesCWE-79
Authorsmadrobot
Template tagscvecve2019jenkinsxsspluginpacketstormvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jenkins:build-metrics:*:*:*:*:*:jenkins:*:*

Source: ProjectDiscovery

References

5