First published: Wed Aug 07 2019(Updated: )
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Pegdown Formatter | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-10374.
The title of the vulnerability is 'A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier'.
The severity of CVE-2019-10374 is medium, with a severity value of 5.4.
Jenkins PegDown Formatter Plugin versions up to and including 1.3 are affected by CVE-2019-10374.
An attacker able to edit descriptions and other fields rendered using the configured markup formatter can exploit CVE-2019-10374 to insert links with the javascript scheme into the Jenkins UI.