CVE-2019-10346
Jenkins Embeddable Build Status Plugin contains Cross-site Scripting
6.1
MEDIUM
CVSS 3.1
EPSS 0.24%
Description
A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.
How to fix CVE-2019-10346
To remediate CVE-2019-10346, upgrade the affected package to a fixed version below.
- —upgrade to 2.0.2 or later
Is CVE-2019-10346 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |