CVE-2024-28160: XSS
Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28160?
CVE-2024-28160 has a medium severity rating due to its potential to cause stored cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2024-28160?
To fix CVE-2024-28160, upgrade the iceScrum Plugin to version 1.1.7 or later, which includes the necessary vulnerability patch.
What does CVE-2024-28160 affect?
CVE-2024-28160 affects Jenkins iceScrum Plugin versions 1.1.6 and earlier.
What kind of vulnerability is CVE-2024-28160?
CVE-2024-28160 is a stored cross-site scripting (XSS) vulnerability that occurs when iceScrum project URLs are not properly sanitized.
Who can exploit CVE-2024-28160?
CVE-2024-28160 can be exploited by attackers who have the ability to configure jobs within Jenkins.