3.5
CVSSv2

CVE-2019-1003013

Published: 06/02/2019 Updated: 25/10/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and previous versions in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/JSONDataWriter.java, blueocean-rest-impl/src/main/java/io/jenkins/blueocean/service/embedded/UserStatePreloader.java, blueocean-web/src/main/resources/io/jenkins/blueocean/PageStatePreloadDecorator/header.jelly that allows attackers with permission to edit a user's description in Jenkins to have Blue Ocean render arbitrary HTML when using it as that user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins blue ocean

redhat openshift container platform 3.11

Vendor Advisories

An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1101 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Exportjava, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfigjava, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ ...