CVE-2024-28149
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
02 / AFFECTED SOFTWARE
Affected packages
18 explicit affected versions
19 explicit affected versions
04 / EVIDENCE
Source records
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2024/03/06/3
- https://www.jenkins.io/security/advisory/2024-03-06/#SECURITY-3301
- https://github.com/jenkinsci/htmlpublisher-plugin
- https://github.com/jenkinsci/htmlpublisher-plugin/commit/8bf2e2297a86ad50f7567fb953b2f8ec18b2891b
- https://nvd.nist.gov/vuln/detail/CVE-2024-28149