CVE-2024-28156: Jenkins Build Monitor View

Medium severity, CVSS 5.4. EPSS: 79.3% chance of exploitation in the next 30 days.

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views.

Affected products

  • Jenkins Build Monitor View: up to and including 1.14-860.vd06ef2568b_3f

Published 2024-03-06. Last modified 2026-06-17.