ZeroHour

CVE-2019-1003042

CVSS 3.0
5.4 medium
EPSS
1%p70
Published
()
Modified
Description

A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.

Vendors
jenkins
Products
lockable resources
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.