First published: Wed Sep 25 2019(Updated: )
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=2.176.3 | |
Jenkins Jenkins | <=2.196 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10403 is classified as a medium severity stored XSS vulnerability.
To fix CVE-2019-10403, upgrade Jenkins to version 2.197 or later, or to LTS version 2.176.4 or later.
CVE-2019-10403 affects Jenkins versions 2.196 and earlier, as well as LTS versions up to 2.176.3.
The impact of CVE-2019-10403 allows potential attackers to execute JavaScript code in the context of the user's browser through stored XSS.
Yes, CVE-2019-10403 can be exploited remotely by users who can control SCM tag names.