CVE-2019-10360: Jenkins m2 Release
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
Affected products
- Jenkins m2 Release: up to and including 0.14.0
Published 2019-07-31. Last modified 2026-06-17.