CVE-2024-28150 Information

Description

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names report names and index page titles shown as part of the report frame resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Reference

https://www.jenkins.io/security/advisory/2024-03-06/#SECURITY-3302

Share on: