PT-2024-22299 · Jenkins · Jenkins Owasp Dependency-Check Plugin+1

Tkmwrbl

·

Published

2024-03-06

·

Updated

2025-01-19

·

CVE-2024-28153

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jenkins OWASP Dependency-Check Plugin versions 5.4.5 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. This occurs because vulnerability metadata from Dependency-Check reports is not properly escaped, allowing for potential malicious script execution.
Recommendations For Jenkins OWASP Dependency-Check Plugin versions 5.4.5 and earlier, update to a version that properly escapes vulnerability metadata to prevent stored XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28153
GHSA-9PP4-MX6X-XH36

Affected Products

Jenkins
Jenkins Owasp Dependency-Check Plugin