CVE-2019-10374: Jenkins Pegdown Formatter
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.
Affected products
- Jenkins Pegdown Formatter: up to and including 1.3
Published 2019-08-07. Last modified 2026-06-17.