First published: Thu Jul 11 2019(Updated: )
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:depgraph-view | <=0.13 | 0.14 |
Jenkins Dependency Graph Viewer | <=0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10349 is rated as a medium severity vulnerability due to its stored cross-site scripting nature.
To fix CVE-2019-10349, update the Jenkins Dependency Graph Viewer Plugin to version 0.14 or later.
CVE-2019-10349 affects versions 0.13 and earlier of the Jenkins Dependency Graph Viewer Plugin.
Yes, CVE-2019-10349 can be exploited remotely by attackers who are able to configure jobs in Jenkins.
CVE-2019-10349 is a stored cross-site scripting vulnerability that allows injection of arbitrary HTML and JavaScript.