Jenkins build-metrics 1.3 is vulnerable to a reflected cross-site scripting vulnerability that allows attackers to inject arbitrary HTML and JavaScript into the web pages the plugin provides.
id: CVE-2019-10475
info:
name: Jenkins build-metrics 1.3 - Cross-Site Scripting
author: madrobo
...