vendor:
Dependency Graph View Plugin
by:
Ishaq Mohammed
5.4
CVSS
MEDIUM
Stored/Persistent XSS
79
CWE
Product Name: Dependency Graph View Plugin
Affected Version From: v0.13
Affected Version To: v0.13
Patch Exists: NO
Related CWE: CVE-2019-10349
CPE: 2.3:a:jenkins:jenkins
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Java
2019
Persistent XSS – Dependency Graph View Plugin(v0.13)
The 'Display Name' field in General Options of the Configure module in Jenkins was found to be accepting arbitrary value which when loaded in the Dependency Graph View module gets execute which makes it vulnerable to a Stored/Persistent XSS.
Mitigation:
As of publication of this advisory, there is no fix.