First published: Fri May 31 2019(Updated: )
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Warnings Next Generation | <=5.0.0 | |
maven/io.jenkins.plugins:warnings-ng | <=5.0.0 | 5.1.0 |
<=5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10325 is a cross-site scripting vulnerability in the Jenkins Warnings NG Plugin 5.0.0 and earlier versions.
CVE-2019-10325 allows an attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.
The severity of CVE-2019-10325 is medium with a CVSS score of 5.4.
To fix CVE-2019-10325, update Jenkins Warnings NG Plugin to version 5.0.1 or later.
You can find more information about CVE-2019-10325 on the following references: [1](http://www.openwall.com/lists/oss-security/2019/05/31/2), [2](http://www.securityfocus.com/bid/108540), [3](https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1373).