CVE-2024-28157

HIGH

Jenkins GitBucket Plugin <= 0.8 - Stored Cross-Site Scripting in Build Views

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-28157. PoCs published by shinigami-777.

AI-analyzed exploit summary This PoC demonstrates a stored XSS vulnerability in Jenkins GitBucket Plugin version 0.8 and earlier. The exploit involves injecting a malicious JavaScript payload into the Gitbucket URL field during job configuration, which executes when the build view is accessed.

Description

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

Exploits (1)

nomisec WORKING POC
by shinigami-777 · poc
https://github.com/shinigami-777/PoC_CVE-2024-28157

This PoC demonstrates a stored XSS vulnerability in Jenkins GitBucket Plugin version 0.8 and earlier. The exploit involves injecting a malicious JavaScript payload into the Gitbucket URL field during job configuration, which executes when the build view is accessed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Jenkins GitBucket Plugin <= 0.8
Auth required
Prerequisites: Access to Jenkins job configuration · GitBucket Plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/03/06/3

Scores

CVSS v3 8.0
EPSS 0.0372
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
jenkins/gitbucket < 0.8
org.jenkins-ci.plugins/gitbucket 0Maven
Published Mar 06, 2024
Tracked Since Feb 18, 2026