Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins html publisher vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2019-10432
Jenkins HTML Publisher Plugin 1.20 and previous versions did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
Jenkins Html Publisher
4
CVSSv2
CVE-2018-1000175
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.
Jenkins Html Publisher
3.5
CVSSv2
CVE-2022-34786
Jenkins Rich Text Publisher Plugin 1.4 and previous versions does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Jenkins Rich Text Publisher
NA
CVE-2024-28151
Jenkins HTML Publisher Plugin 1.32 and previous versions archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exist...
NA
CVE-2024-28149
Jenkins HTML Publisher Plugin 1.16 up to and including 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system e...
NA
CVE-2024-28150
Jenkins HTML Publisher Plugin 1.32 and previous versions does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started