Jenkins HTML Publisher Plugin vulnerable to stored XSS
CVE-2024-28150
Currently unrated 🤨
Summary
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Version(s)
Jenkins HTML Publisher Plugin <= 1.32
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database