Vulnerabilities
Vulnerable Software
Jenkins:  >> Html Publisher  >> 1.14  Security Vulnerabilities
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVSS Score
4.7
EPSS Score
0.002
Published
2024-03-06
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-03-06
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-10-01
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-05-08


Contact Us

Shodan ® - All rights reserved