CVE-2019-1003042
Estado: ModificadaMedia (5.4)—
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.37%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://www.openwall.com/lists/oss-security/2019/03/28/2
- http://www.securityfocus.com/bid/107628
- https://access.redhat.com/errata/RHSA-2019:1423
- https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1361
- http://www.openwall.com/lists/oss-security/2019/03/28/2
- http://www.securityfocus.com/bid/107628
- https://access.redhat.com/errata/RHSA-2019:1423
- https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1361
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-1003042",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "jenkinsci-cert@googlegroups.com",
"affectedData": [
{
"vendor": "Jenkins project",
"product": "Jenkins Lockable Resources Plugin",
"versions": [
{
"status": "affected",
"version": "2.4 and earlier"
}
]
}
]
}
],
"published": "2019-03-28T18:29:00.343",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2019/03/28/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.securityfocus.com/bid/107628",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1423",
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1361",
"tags": [
"Vendor Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2019/03/28/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/107628",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1423",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jenkins.io/security/advisory/2019-03-25/#SECURITY-1361",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin."
},
{
"lang": "es",
"value": "Una vulnerabilidad de Cross-Site Scripting (XSS) en Jenkins Lockable Resources, en versiones 2.4 y anteriores, permite a los atacantes capacitados para controlar los nombres de recursos inyectar código JavaScript arbitrario en las páginas web renderizadas por el plugin."
}
],
"lastModified": "2026-06-17T02:09:36.003",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:lockable_resources:*:*:*:*:*:jenkins:*:*",
"vulnerable": true,
"matchCriteriaId": "2D4D4C8E-9AC0-4F58-82F2-C98DD0690ADF",
"versionEndIncluding": "2.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}