Jenkins · Jenkins Embeddable Build Status Plugin · CVE-2019-10346
**Name of the Vulnerable Software and Affected Versions**
Jenkins Embeddable Build Status Plugin versions 2.0.1 and earlier
**Description**
A reflected cross site scripting issue allows attackers to inject arbitrary HTML and JavaScript into the response of the plugin. This enables them to execute malicious scripts on the client-side.
**Recommendations**
For Jenkins Embeddable Build Status Plugin versions 2.0.1 and earlier, update to a version later than 2.0.1 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.