← back
CVE-2019-10403

CVE-2019-10403

EPSS 1.0%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Sep 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →