PT-2024-2110 · Jenkins · Jenkins Html Publisher Plugin+1

Kevin Guerroudj

·

Published

2024-03-06

·

Updated

2025-05-06

·

CVE-2024-28149

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins HTML Publisher Plugin versions 1.16 through 1.32
Description The issue arises from the plugin's failure to properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks. This can also enable attackers to determine whether a specific path exists on the Jenkins controller file system.
Recommendations For Jenkins HTML Publisher Plugin versions 1.16 through 1.32, update to a version outside of this range to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-02006
CVE-2024-28149
GHSA-8VCG-V7G4-3VR7
RHSA-2024:3634
RHSA-2024:3635
RHSA-2024:3636
RHSA-2024:4597

Affected Products

Jenkins
Jenkins Html Publisher Plugin