PT-2024-22302 · Jenkins · Jenkins Build Monitor View Plugin+1

Wadeck Follonier

·

Published

2024-03-06

·

Updated

2025-01-19

·

CVE-2024-28156

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Build Monitor View Plugin versions 1.14-860.vd06ef2568b 3f and earlier
Description The issue results from the failure to escape Build Monitor View names, leading to a stored cross-site scripting (XSS) vulnerability. This vulnerability can be exploited by attackers who have the ability to configure Build Monitor Views.
Recommendations For Jenkins Build Monitor View Plugin versions 1.14-860.vd06ef2568b 3f and earlier, consider disabling the configuration of Build Monitor Views until a patch is available to prevent exploitation of the stored XSS vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28156
GHSA-5J5R-6MV9-M255

Affected Products

Jenkins
Jenkins Build Monitor View Plugin