Beveiligingsadvies

CVE-2019-10335

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-06-11 13:15:26
Laatst bijgewerkt 2024-08-04 22:17:20
Toegewezen door jenkins
CVSS-score geen score
Status PUBLISHED

Beschrijving

A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages.