CVE-2024-28156

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-28156
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-28156.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-28156
Aliases
Published
2024-03-06T17:15:10Z
Modified
2025-03-27T22:47:22.995952Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views.

References

Affected packages

Git / github.com/jenkinsci/build-monitor-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/build-monitor-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*

1.14-650.vb_43f505305f6
1.14-651.v429b_16b_db_60e
1.14-653.va_1c684a_30b_ff
1.14-667.vfb_ef30539e07
1.14-681.vd6817317a_2b_7
1.14-702.vf34cc4398955
1.14-717.v3efcdffe8d58
1.14-740.v1df20e5c64b_b_
1.14-744.v35fd6fa_a_26b_2
1.14-745.ve2023a_305f40
1.14-826.vb_a_c11536174d
1.14-860.vd06ef2568b_3f