Related Vulnerabilities: CVE-2019-10383  

Jenkins did not properly escape the update site URL in some status messages shown in the update center, resulting in a stored cross-site scripting vulnerability that is exploitable by administrators and affects other administrators.

Severity Low

Remote Yes

Type Cross-site scripting

Description

Jenkins did not properly escape the update site URL in some status messages shown in the update center, resulting in a stored cross-site scripting vulnerability that is exploitable by administrators and affects other administrators.

AVG-1030 jenkins 2.189-1 Medium Vulnerable

https://jenkins.io/security/advisory/2019-08-28/