CVE-2024-28150: XSS
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28150?
CVE-2024-28150 is a stored cross-site scripting (XSS) vulnerability affecting Jenkins HTML Publisher Plugin versions 1.32 and earlier.
How do I fix CVE-2024-28150?
To fix CVE-2024-28150, upgrade the Jenkins HTML Publisher Plugin to version 1.32.1 or later.
Who can exploit CVE-2024-28150?
CVE-2024-28150 can be exploited by attackers who have Item/Configure permission in Jenkins.
What are the potential impacts of CVE-2024-28150?
The potential impacts of CVE-2024-28150 include unauthorized execution of scripts in the browser of users accessing the affected reports.
What software versions are affected by CVE-2024-28150?
CVE-2024-28150 affects Jenkins HTML Publisher Plugin versions up to and including 1.32.