CVE Published: 06/03/2024 |
CVE Updated: 22/11/2024 |
CVE Year: 2024 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins HTML Publisher Plugin Status : PUBLISHED
CVE-2024-28150 Description
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.