Lucene search

K
cvelistJenkinsCVELIST:CVE-2019-10336
HistoryJun 11, 2019 - 1:15 p.m.

CVE-2019-10336

2019-06-1113:15:26
jenkins
www.cve.org
1

0.002 Low

EPSS

Percentile

52.8%

A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this plugin.

CNA Affected

[
  {
    "product": "Jenkins ElectricFlow Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "status": "affected",
        "version": "1.1.6 and earlier"
      }
    ]
  }
]

0.002 Low

EPSS

Percentile

52.8%

Related for CVELIST:CVE-2019-10336