Proof of Concept for CVE-2024-28157

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

Published 6 Mar 2024Updated 17 Jun 20268 sources
CVSS 8.0 ✓ VERIFIED REFERENCE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.