CVE-2024-23905

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:red_hat_dependency_analytics:*:*:*:*:*:jenkins:*:*

History

29 Jan 2024, 19:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Jenkins
Jenkins red Hat Dependency Analytics
Summary
  • (es) El complemento Jenkins Red Hat Dependency Analytics 0.7.1 y versiones anteriores deshabilita mediante programación la protección de la política de seguridad de contenido para el contenido generado por el usuario en espacios de trabajo, artefactos archivados, etc. que Jenkins ofrece para descargar.
References () http://www.openwall.com/lists/oss-security/2024/01/24/6 - () http://www.openwall.com/lists/oss-security/2024/01/24/6 - Mailing List, Third Party Advisory
References () https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3322 - () https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3322 - Vendor Advisory
CWE CWE-79
CPE cpe:2.3:a:jenkins:red_hat_dependency_analytics:*:*:*:*:*:jenkins:*:*

24 Jan 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-24 18:15

Updated : 2024-01-29 19:26


NVD link : CVE-2024-23905

Mitre link : CVE-2024-23905

CVE.ORG link : CVE-2024-23905


JSON object : View

Products Affected

jenkins

  • red_hat_dependency_analytics
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')