CVE-2019-1003042
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.4%
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
nono source reports it
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
Affected products
Jenkins project · Jenkins Lockable Resources Plugin