FlawAtlas
Search the atlas
CVE-2024-28149 Moderate

CVE-2024-28149

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.

Exploit probability 0.7%
Published March 6, 2024
Required by Not available
Last source change July 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

18 explicit affected versions

Maven org.jenkins-ci.plugins:htmlpublisher

19 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-28149

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.

View original source
Open Source Vulnerabilities GHSA-8vcg-v7g4-3vr7

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.

View original source

05 / REFERENCES

Further evidence