Description
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3149 | Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties. |
Github GHSA |
GHSA-88qj-3q6h-8m5q | Jenkins Build Environment Plugin vulnerable to Cross-site Scripting |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.568Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10395
No data.
Status : Modified
Published: 2019-09-12T14:15:11.473
Modified: 2024-11-21T04:19:02.610
Link: CVE-2019-10395
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA