CVE-2019-10403 Information
Feb 14, 2021
cve
Description
Jenkins 2.196 and earlier LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
http://www.openwall.com/lists/oss-security/2019/09/25/3 https://jenkins.io/security/advisory/2019-09-25/SECURITY-153720(1)
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: