Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS00d2o3LXJoNWgtNXFtcs4AAhRC

Jenkins Dependency Graph Viewer Plugin contains Cross-site Scripting

A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

Permalink: https://github.com/advisories/GHSA-4wj7-rh5h-5qmr
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00d2o3LXJoNWgtNXFtcs4AAhRC
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 7 months ago


CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-4wj7-rh5h-5qmr, CVE-2019-10349
References: Repository: https://github.com/jenkinsci/depgraph-view-plugin
Blast Radius: 1.0

Affected Packages

maven:org.jenkins-ci.plugins:depgraph-view
Affected Version Ranges: <= 0.13
Fixed in: 0.14