Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1047 | Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |
Github GHSA |
GHSA-xrrw-9j78-hpf3 | Jenkins HTML Publisher Plugin Stored XSS vulnerability |
Tue, 06 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins html Publisher |
|
| CPEs | cpe:2.3:a:jenkins:html_publisher:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins html Publisher |
Fri, 22 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-13T17:47:18.356Z
Reserved: 2024-03-05T19:29:05.204Z
Link: CVE-2024-28150
Updated: 2024-08-02T00:48:49.113Z
Status : Analyzed
Published: 2024-03-06T17:15:10.510
Modified: 2025-05-06T20:45:06.060
Link: CVE-2024-28150
OpenCVE Enrichment
No data.
EUVD
Github GHSA