CVE-2019-10403: XSS
Published Sep 25, 2019
·Updated
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
Affected Software
2 affected components
Jenkins Jenkins<=2.176.3
Jenkins Jenkins<=2.196
Event History
Sep 25, 2019
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10403?
CVE-2019-10403 is classified as a medium severity stored XSS vulnerability.
2
How do I fix CVE-2019-10403?
To fix CVE-2019-10403, upgrade Jenkins to version 2.197 or later, or to LTS version 2.176.4 or later.
3
Who is affected by CVE-2019-10403?
CVE-2019-10403 affects Jenkins versions 2.196 and earlier, as well as LTS versions up to 2.176.3.
4
What is the impact of CVE-2019-10403?
The impact of CVE-2019-10403 allows potential attackers to execute JavaScript code in the context of the user's browser through stored XSS.
5
Can CVE-2019-10403 be exploited remotely?
Yes, CVE-2019-10403 can be exploited remotely by users who can control SCM tag names.