← back
CVE-2019-10475

CVE-2019-10475

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 58%
from disclosure to weapon14 days
Published on NVDOct 23
1st PoC+14d
exploitation probability
58%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.