CVE-2019-10475 describes a reflected cross-site scripting (XSS) vulnerability in the Jenkins build-metrics plugin, allowing attackers to inject arbitrary HTML and JavaScript into affected web pages. Rated 6.1 MEDIUM (CVSSv3.1), this vulnerability requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), potentially leading to information disclosure and integrity compromise (C:L/I:L). While not on CISA's KEV catalog or actively exploited, public exploit code exists via ExploitDB and Nuclei templates, indicating readily available methods for exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3CPE matchmatch criteria | cpe:2.3:a:jenkins:build-metrics:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.