CVE-2024-28157: Jenkins Gitbucket

High severity, CVSS 8.0. EPSS: 1.3% chance of exploitation in the next 30 days.

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

Affected products

  • Jenkins Gitbucket: up to and including 0.8

Published 2024-03-06. Last modified 2026-06-17.