CVE-2019-10401: XSS
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Configure).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10401?
CVE-2019-10401 is a vulnerability in Jenkins 2.196 and earlier LTS 2.176.3 and earlier that allows stored cross-site scripting (XSS) attacks.
How does the f:expandableTextBox form control interpret content in Jenkins?
The f:expandableTextBox form control in Jenkins 2.196 and earlier LTS 2.176.3 and earlier interprets its content as HTML when expanded.
Who can exploit the stored XSS vulnerability in Jenkins?
Users with permission to define the contents of the f:expandableTextBox form control, typically Job/Configure, can exploit the stored XSS vulnerability.
What is the severity level of CVE-2019-10401?
CVE-2019-10401 has a severity level of medium.
How can I mitigate CVE-2019-10401 in Jenkins?
To mitigate CVE-2019-10401, upgrade Jenkins to version 2.196 or later LTS 2.176.3 or later.