CVE-2019-10349
Status: ModifiedMedium (5.4)—
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Base score: 5.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.89%
- Percentile among all scored CVEs: 90
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
- http://packetstormsecurity.com/files/153610/Jenkins-Dependency-Graph-View-0.13-Cross-Site-Scripting.html
- http://www.openwall.com/lists/oss-security/2019/07/11/4
- http://www.securityfocus.com/bid/109156
- https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1177
- http://packetstormsecurity.com/files/153610/Jenkins-Dependency-Graph-View-0.13-Cross-Site-Scripting.html
- http://www.openwall.com/lists/oss-security/2019/07/11/4
- http://www.securityfocus.com/bid/109156
- https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1177
Raw JSON (NVD)
Show
{
"id": "CVE-2019-10349",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "jenkinsci-cert@googlegroups.com",
"affectedData": [
{
"vendor": "Jenkins project",
"product": "Jenkins Dependency Graph Viewer Plugin",
"versions": [
{
"status": "affected",
"version": "0.13 and earlier"
}
]
}
]
}
],
"published": "2019-07-11T14:15:10.960",
"references": [
{
"url": "http://packetstormsecurity.com/files/153610/Jenkins-Dependency-Graph-View-0.13-Cross-Site-Scripting.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2019/07/11/4",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.securityfocus.com/bid/109156",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1177",
"tags": [
"Vendor Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://packetstormsecurity.com/files/153610/Jenkins-Dependency-Graph-View-0.13-Cross-Site-Scripting.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2019/07/11/4",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/109156",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1177",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins."
},
{
"lang": "es",
"value": "Una vulnerabilidad de tipo cross site scripting almacenado en el Plugin Dependency Graph Viewer versión 0.13 y anteriores de Jenkins, permitió a los atacantes capaces de configurar trabajos en Jenkins inyectar HTML y JavaScript arbitrario en las páginas web provistas del plugin en Jenkins."
}
],
"lastModified": "2026-06-17T02:10:45.927",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:dependency_graph_viewer:*:*:*:*:*:jenkins:*:*",
"vulnerable": true,
"matchCriteriaId": "035A0EE9-9BE1-467B-A6DF-04A33E4B9DE1",
"versionEndIncluding": "0.13"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}