A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
References
Link Resource
http://www.openwall.com/lists/oss-security/2019/07/11/4 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/109156 Broken Link Third Party Advisory VDB Entry
https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1419 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2019-07-11T13:55:17

Updated: 2023-10-24T16:47:49.887Z

Reserved: 2019-03-29T00:00:00


Link: CVE-2019-10346

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-07-11T14:15:10.740

Modified: 2023-10-25T18:16:17.260


Link: CVE-2019-10346

JSON object: View

cve-icon Redhat Information

No data.

CWE