cbcvebase.
CVE-2024-28149
published 2024-03-06

CVE-2024-28149: Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
0.70%
48.8th percentile
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsappspider_plugin
jenkinsbitbucket_branch_source_plugin
jenkinsbuild_monitor_view_plugin
jenkinsdelphix_plugin
jenkinsgitbucket_plugin
jenkinshtml_publisher>= 1.16 < 1.32.11.32.1
jenkinshtml_publisher_plugin
jenkinsimproper_input_sanitization_in_html_publisher_plugin
jenkinsmq_notifier_plugin
jenkinsowasp_dependency-check_plugin
jenkinssubversion_partial_release_manager_plugin
jenkinstls_certificate_validation_in_delphix_plugin
jenkins_projectjenkins_html_publisher_plugin1.16 – 1.32

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.