CVE-2024-54003: Jenkins Simple Queue

High severity, CVSS 8.0. EPSS: 80.1% chance of exploitation in the next 30 days.

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.

Affected products

  • Jenkins Simple Queue: up to and including 1.4.4

Published 2024-11-27. Last modified 2026-06-17.