PT-2019-14717 · Jenkins · Jenkins Buildgraph-View Plugin+1

Viktor Gazdag

·

Published

2019-12-17

·

Updated

2023-11-02

·

CVE-2019-16562

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins buildgraph-view Plugin versions 1.8 and earlier
Description The issue results in a stored cross-site scripting vulnerability. It occurs because the plugin does not escape the description of builds shown in its view. This makes it exploitable by users who have the ability to change build descriptions.
Recommendations For Jenkins buildgraph-view Plugin versions 1.8 and earlier, update to a version later than 1.8 to resolve the issue. As a temporary workaround, consider restricting the ability to change build descriptions to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-16562
GHSA-4J4G-FP93-QVRW

Affected Products

Jenkins
Jenkins Buildgraph-View Plugin