Medium severity5.4NVD Advisory· Published Apr 10, 2019· Updated Jun 17, 2026
CVE-2019-1003050
CVE-2019-1003050
Description
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.164.2 | 2.164.2 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.165, < 2.172 | 2.172 |
Affected products
6cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <=2.164.1
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*range: <=2.171
- (no CPE)range: 2.171 and earlier, LTS 2.164.1 and earlier
- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- access.redhat.com/errata/RHBA-2019:1605nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-qpg9-83fv-x9chghsaADVISORY
- jenkins.io/security/advisory/2019-04-10/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-1003050ghsaADVISORY
- www.securityfocus.com/bid/107889nvdBroken LinkWEB
- github.com/jenkinsci/jenkins/commit/8eb632dda219ec8796420ce58d9564cddf8f8f93ghsaWEB
- github.com/jenkinsci/jenkins/commit/d393c7e9ba3ec44953ef1f8b11839421e2649ee7ghsaWEB
News mentions
0No linked articles in our index yet.