CVE-2024-28149 is a cross-site scripting (XSS) vulnerability affecting Jenkins HTML Publisher Plugin versions 1.16 through 1.32. Attackers with Item/Configure permission can exploit this flaw to inject malicious scripts and determine the existence of paths on the Jenkins controller file system. Rated as Medium severity (CVSS 6.5), this vulnerability has a low impact on confidentiality and availability, with no known public exploits, Metasploit modules, or significant community discussion at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.16, < 1.32.1CPE matchmatch criteria | cpe:2.3:a:jenkins:html_publisher:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.