CVE-2019-10335
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2019-10335. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Jenkins ElectricFlow Plugin is vulnerable to stored cross site scripting vulnerability
GHSA-fx9p-2qvx-pgjvAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Advisory provided by GitHub Security Advisory Database. Published: May 24, 2022, Modified: October 26, 2023