Vulnerability record · CVE-2019-10475 · published 23 October 2019
CVE-2019-10475: Jenkins build-metrics Plugin reflected XSS
Jenkins · Build Metrics
The Jenkins build-metrics Plugin reflects attacker-controlled input into web pages it serves, allowing arbitrary HTML and JavaScript injection. Because the plugin runs inside the Jenkins UI, a successful attack executes script in the context of an authenticated Jenkins session. The record does not state which plugin versions are affected beyond the 1.3 referenced in the third-party advisory.
Description
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it 6.1 medium and it requires user interaction, but the high EPSS percentile and Jenkins' sensitive position justify prompt patching.
What it is
The Jenkins build-metrics Plugin reflects attacker-controlled input into web pages it serves, allowing arbitrary HTML and JavaScript injection. Because the plugin runs inside the Jenkins UI, a successful attack executes script in the context of an authenticated Jenkins session. The record does not state which plugin versions are affected beyond the 1.3 referenced in the third-party advisory.
Impact
An attacker can run script in a victim's browser within the Jenkins origin, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change (S:C) reflects that the injected content can affect resources beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL that the victim must open while logged into Jenkins; the vector shows no privileges required (PR:N) but user interaction is required (UI:R). No authentication is needed to deliver the payload, only for the victim's session to be useful.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.57735, ~99th percentile), and references are vendor and third-party advisories with no public exploit tag, so exploitation is plausible but not confirmed by this record.
What to do
- Upgrade the build-metrics Plugin to a version that fixes SECURITY-1490, per the Jenkins advisory of 2019-10-23.
- If no fixed version is available, disable or remove the build-metrics Plugin from Jenkins.
- Restrict access to the Jenkins UI to trusted networks and require authentication for all users.
- Deploy a Content-Security-Policy that blocks inline script on Jenkins pages where feasible.
- Instruct users not to follow untrusted links while logged into Jenkins.
Detection
- Search Jenkins access logs for requests to build-metrics plugin endpoints containing script tags, event handlers, or encoded payloads in query parameters.
- Monitor for anomalous authenticated Jenkins sessions, especially requests originating from unusual referrers or IPs.
- Review Jenkins audit logs for plugin configuration or user changes made shortly after suspicious build-metrics requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155200/Jenkins-Build-Metrics-1.3-Cross-Site-Scripting.html | Third Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2019/10/23/2 | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1490 | Vendor Advisory |
| http://packetstormsecurity.com/files/155200/Jenkins-Build-Metrics-1.3-Cross-Site-Scripting.html | Third Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2019/10/23/2 | Mailing ListThird Party Advisory |
| https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1490 | Vendor Advisory |
Track CVE-2019-10475 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-10475), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.