CVE-2024-54003: Jenkins Simple Queue
High severity, CVSS 8.0. EPSS: 80.1% chance of exploitation in the next 30 days.
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.
Affected products
- Jenkins Simple Queue: up to and including 1.4.4
Published 2024-11-27. Last modified 2026-06-17.