cbcvebase.
CVE-2024-28150
published 2024-03-06

CVE-2024-28150: Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a…

medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsappspider_plugin
jenkinsbitbucket_branch_source_plugin
jenkinsbuild_monitor_view_plugin
jenkinsdelphix_plugin
jenkinsgitbucket_plugin
jenkinshtml_publisher< 1.32.11.32.1
jenkinshtml_publisher_plugin
jenkinsimproper_input_sanitization_in_html_publisher_plugin
jenkinsmq_notifier_plugin
jenkinsowasp_dependency-check_plugin
jenkinssubversion_partial_release_manager_plugin
jenkinstls_certificate_validation_in_delphix_plugin
jenkins_projectjenkins_html_publisher_plugin<= 1.32