CVE-2019-10349
Jenkins Dependency Graph Viewer Plugin contains Cross-site Scripting
5.4
MEDIUM
CVSS 3.1
EPSS 0.78%
Description
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
How to fix CVE-2019-10349
To remediate CVE-2019-10349, upgrade the affected package to a fixed version below.
- —upgrade to 0.14 or later
Is CVE-2019-10349 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.14
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |