Medium severity4.8NVD Advisory· Published Aug 28, 2019· Updated Jun 17, 2026
CVE-2019-10383
CVE-2019-10383
Description
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.176.3 | 2.176.3 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.177, < 2.192 | 2.192 |
Affected products
7cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*range: <=2.191
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <=2.176.2
- (no CPE)range: 2.191 and earlier, LTS 2.176.2 and earlier
- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2019/08/28/4nvdMailing ListThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2789nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3144nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-9m48-54pj-h248ghsaADVISORY
- jenkins.io/security/advisory/2019-08-28/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10383ghsaADVISORY
- github.com/jenkinsci/jenkins/commit/fb88530f77d38660ab2aae8c2e842944f0fb1507ghsaWEB
News mentions
0No linked articles in our index yet.