First published: Wed Mar 06 2024(Updated: )
Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:icescrum | <=1.1.6 | |
Jenkins iceScrum | <=1.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28160 has a medium severity rating due to its potential to cause stored cross-site scripting (XSS) vulnerabilities.
To fix CVE-2024-28160, upgrade the iceScrum Plugin to version 1.1.7 or later, which includes the necessary vulnerability patch.
CVE-2024-28160 affects Jenkins iceScrum Plugin versions 1.1.6 and earlier.
CVE-2024-28160 is a stored cross-site scripting (XSS) vulnerability that occurs when iceScrum project URLs are not properly sanitized.
CVE-2024-28160 can be exploited by attackers who have the ability to configure jobs within Jenkins.