PT-2024-22306 · Jenkins · Jenkins Icescrum Plugin+1

Yaroslav Afenkin

·

Published

2024-03-06

·

Updated

2024-11-07

·

CVE-2024-28160

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins iceScrum Plugin versions 1.1.6 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin does not sanitize iceScrum project URLs on build views. Attackers who can configure jobs may exploit this.
Recommendations For versions 1.1.6 and earlier, update to a version that fixes the sanitization of iceScrum project URLs to prevent stored XSS attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28160
GHSA-2PC2-H97H-2MMW

Affected Products

Jenkins
Jenkins Icescrum Plugin