3.5
CVSSv2

CVE-2019-10432

Published: 01/10/2019 Updated: 25/10/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Jenkins HTML Publisher Plugin 1.20 and previous versions did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins html publisher

Vendor Advisories

Synopsis Important: OpenShift Container Platform 311 jenkins-2-plugins security update Type/Severity Security Advisory: Important Topic An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as having a security impact o ...
Synopsis Important: OpenShift Container Platform 42 jenkins-2-plugins security update Type/Severity Security Advisory: Important Topic An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: OpenShift Container Platform 41 jenkins-2-plugins security update Type/Severity Security Advisory: Important Topic An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of ...

Mailing Lists

Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software The following releases contain fixes for security vulnerabilities: * HTML Publisher Plugin 121 * Script Security Plugin 165 Additionally, we announce unresolved security issues in the following plugins: * Di ...