Lucene search

K
osvGoogleOSV:GHSA-8VCG-V7G4-3VR7
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins HTML Publisher Plugin does not properly sanitize input

2024-03-0618:30:38
Google
osv.dev
7
jenkins
html publisher
input sanitation
vulnerability
xss
file system.

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%