Medium severity5.4NVD Advisory· Published Sep 12, 2019· Updated Jun 17, 2026
CVE-2019-10395
CVE-2019-10395
Description
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:build-environmentMaven | < 1.7 | 1.7 |
Affected products
3- cpe:2.3:a:jenkins:build_environment:*:*:*:*:*:jenkins:*:*Range: <=1.6
- Range: 1.6 and earlier
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2019/09/12/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-88qj-3q6h-8m5qghsaADVISORY
- jenkins.io/security/advisory/2019-09-12/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10395ghsaADVISORY
- github.com/jenkinsci/build-environment-plugin/commit/c9797608e839d0dce1957e3c1b512b872839e603ghsaWEB
News mentions
0No linked articles in our index yet.