Lucene search

K
vulnrichmentJenkinsVULNRICHMENT:CVE-2024-28150
HistoryMar 06, 2024 - 5:01 p.m.

CVE-2024-28150

2024-03-0617:01:53
jenkins
github.com
1
jenkins
html publisher
xss

AI Score

5.3

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

AI Score

5.3

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial