CVE-2024-28157
EUVD-2024-083106.03.2024, 17:15
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | gitbucket | 𝑥 ≤ 0.8 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jenkins_project | jenkins_gitbucket_plugin | 𝑥 ≤ 0.8 | ADP |