CVE-2024-28157 is a stored cross-site scripting vulnerability in Jenkins GitBucket Plugin version 0.8 and earlier. The plugin does not sanitize GitBucket URL values rendered in build views. An attacker with permission to configure Jenkins jobs can store a crafted URL that executes attacker-controlled script when a user views the affected build view.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This 10-file repository is a reproducible lab and documentation package for CVE-2024-28157, a stored XSS flaw in Jenkins GitBucket Plugin versions 0.8 and earlier. It contains no standalone remote exploit client; instead, it documents the manual injection of `javascript:alert(7*7)` into a Freestyle job's GitBucket URL configuration and supplies a Docker environment to reproduce the behavior. `poc/download-plugins` downloads GitBucket 0.7 plus old Git and SCM API dependencies, while `poc/Dockerfile` downloads Jenkins 1.609.3 and `poc/entrypoint` installs the plugins into Jenkins home before launching Jenkins. `docker-compose.yml` exposes the Jenkins UI on port 8080 and inbound-agent port 50000. The remaining README, BugOverview, SECURITY, and report.html files explain the vulnerability, reproduction procedure, and a static Vercel-hostable report. Successful exploitation executes attacker-selected JavaScript in every visitor's browser when the affected job page is viewed; the bundled payload is a harmless alert demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.