Lucene search

K
osvGoogleOSV:GHSA-XRRW-9J78-HPF3
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins HTML Publisher Plugin Stored XSS vulnerability

2024-03-0618:30:38
Google
osv.dev
5
jenkins
html publisher plugin
xss
vulnerability
job names
report titles
index page
stored
cross-site scripting
attackers
permission
software

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%