Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tkmwrbl

#38073of 53,630
7.3Total CVSS
Vulnerabilities · 1
PT-2024-22299
7.3
2024-03-06
Jenkins · Jenkins Owasp Dependency-Check Plugin · CVE-2024-28153
**Name of the Vulnerable Software and Affected Versions** Jenkins OWASP Dependency-Check Plugin versions 5.4.5 and earlier **Description** The issue is related to a stored cross-site scripting (XSS) vulnerability. This occurs because vulnerability metadata from Dependency-Check reports is not properly escaped, allowing for potential malicious script execution. **Recommendations** For Jenkins OWASP Dependency-Check Plugin versions 5.4.5 and earlier, update to a version that properly escapes vulnerability metadata to prevent stored XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.