CVE-2019-1003050
10.04.2019, 21:29
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 ≤ 2.164.1 |
jenkins | jenkins | 𝑥 ≤ 2.171 |
oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
redhat | openshift_container_platform | 3.11 |
𝑥
= Vulnerable software versions
References