CVE-2019-10383
28.08.2019, 16:15
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 ≤ 2.176.2 |
jenkins | jenkins | 𝑥 ≤ 2.191 |
oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
redhat | openshift_container_platform | 3.11 |
redhat | openshift_container_platform | 4.1 |
𝑥
= Vulnerable software versions
References