CVE-2019-10475
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 58%
from disclosure to weapon14 days
Published on NVDOct 23
1st PoC+14d
exploitation probability
58%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
Affected products
Jenkins project · Jenkins build-metrics Pluginpublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/47598unverifiedgithubgithub.com/vesche/CVE-2019-10475★ 13cve_referencepacketstormsecurity.com/files/155200/Jenkins-Build-Metrics-1.3-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.