Medium severity5.4NVD Advisory· Published Mar 28, 2019· Updated Jun 17, 2026
CVE-2019-1003042
CVE-2019-1003042
Description
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.6wind.jenkins:lockable-resourcesMaven | < 2.5 | 2.5 |
Affected products
3- Range: 2.4 and earlier
- cpe:2.3:a:jenkins:lockable_resources:*:*:*:*:*:jenkins:*:*Range: <=2.4
Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2019/03/28/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/107628nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-wqjj-c9cx-q7cfghsaADVISORY
- jenkins.io/security/advisory/2019-03-25/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-1003042ghsaADVISORY
- access.redhat.com/errata/RHSA-2019:1423nvdWEB
- github.com/jenkinsci/lockable-resources-plugin/commit/4f401e250eb9e865e951b069255fea7052423739ghsaWEB
News mentions
0No linked articles in our index yet.