CVE-2019-10475: XSS
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
Other sources
Jenkins build-metrics Plugin does not properly escape the label query parameter, resulting in a reflected cross-site scripting vulnerability.
As of publication of this advisory, there is no fix.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10475?
CVE-2019-10475 is considered a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2019-10475?
To mitigate CVE-2019-10475, update the Jenkins build-metrics Plugin to version 1.4 or higher.
What causes CVE-2019-10475?
CVE-2019-10475 is caused by improper escaping of the 'label' query parameter, allowing for injection of arbitrary HTML and JavaScript.
What type of vulnerability is CVE-2019-10475?
CVE-2019-10475 is categorized as a reflected cross-site scripting (XSS) vulnerability.
Which software versions are affected by CVE-2019-10475?
CVE-2019-10475 affects versions of the Jenkins build-metrics Plugin up to and including 1.3.