4.8
CVSSv3

CVE-2019-1003014

Published: 06/02/2019 Updated: 25/10/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and previous versions in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins config file provider

redhat openshift container platform 3.11

Vendor Advisories

An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 341 and earlier in src/main/resources/lib/configfiles/configfilesjelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file ...