CVE-2024-23905

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:red_hat_dependency_analytics:*:*:*:*:*:jenkins:*:*

History

29 Jan 2024, 19:26

Type Values Removed Values Added
Summary
  • (es) El complemento Jenkins Red Hat Dependency Analytics 0.7.1 y versiones anteriores deshabilita mediante programación la protección de la política de seguridad de contenido para el contenido generado por el usuario en espacios de trabajo, artefactos archivados, etc. que Jenkins ofrece para descargar.
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () http://www.openwall.com/lists/oss-security/2024/01/24/6 - () http://www.openwall.com/lists/oss-security/2024/01/24/6 - Mailing List, Third Party Advisory
References () https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3322 - () https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3322 - Vendor Advisory
CPE cpe:2.3:a:jenkins:red_hat_dependency_analytics:*:*:*:*:*:jenkins:*:*
First Time Jenkins red Hat Dependency Analytics
Jenkins

24 Jan 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-24 18:15

Updated : 2024-01-29 19:26


NVD link : CVE-2024-23905

Mitre link : CVE-2024-23905

CVE.ORG link : CVE-2024-23905


JSON object : View

Products Affected

jenkins

  • red_hat_dependency_analytics
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')