CVE-2019-10475
Jenkins build-metrics Plugin reflected cross-site scripting vulnerability
Record summary
CVE-2019-10475 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Description
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Jenkins build-metrics PluginBrowse Jenkins project / Jenkins build-metrics Plugin | CVE List | 1.3 and earlier | affected |
org.jenkins-ci.plugins:build-metricsBrowse Maven / org.jenkins-ci.plugins:build-metrics | GitHub Advisory | Through 1.3 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBJenkins build-metrics plugin 1.3 - 'label' Cross-Site ScriptingExploitDB exploitby vescheNot analyzed1 file
Repository PoCs
GitHubvesche/CVE-2019-10475Repository PoCby vescheStars: 13Not analyzed5 files
Nuclei templates
1ProjectDiscoveryMEDIUMJenkins build-metrics 1.3 - Cross-Site ScriptingCVSS 6.1
Jenkins build-metrics 1.3 is vulnerable to a reflected cross-site scripting vulnerability that allows attackers to inject arbitrary HTML and JavaScript into the web pages the plugin provides.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser, leading to potential data theft or unauthorized actions.
Remediation
Upgrade to a patched version of the Jenkins build-metrics plugin or apply the necessary fixes provided by the vendor.
Source: ProjectDiscovery