CVE-2019-10402: XSS
Published Sep 25, 2019
·Updated
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.
Affected Software
4 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core>=2.177<=2.196
2.197
maven/org.jenkins-ci.main:jenkins-core<=2.176.3
2.176.4
Jenkins Jenkins<=2.176.3
Jenkins Jenkins<=2.196
Event History
Sep 25, 2019
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
May 24, 2022
Advisory Published
10:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-10402?
CVE-2019-10402 is considered a medium severity stored XSS vulnerability.
2
How do I fix CVE-2019-10402?
To fix CVE-2019-10402, upgrade Jenkins to version 2.197 or version 2.176.4.
3
Who is affected by CVE-2019-10402?
CVE-2019-10402 affects users of Jenkins versions 2.196 and earlier, including LTS versions 2.176.3 and earlier.
4
What type of vulnerability is CVE-2019-10402?
CVE-2019-10402 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2019-10402 be exploited remotely?
Yes, CVE-2019-10402 can be exploited remotely by users who have permission to define the contents of the f:combobox form control.