PT-2024-2759 · Red Hat+2 · Jenkins Red Hat Dependency Analytics Plugin+2

Pierre Beitz

·

Published

2024-01-24

·

Updated

2024-04-11

·

CVE-2024-23905

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Red Hat Dependency Analytics Plugin versions 0.7.1 and earlier
Description The issue is related to the lack of Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. This allows a remote attacker to perform cross-site scripting (XSS) attacks with the possibility of managing files in workspaces. The Red Hat Dependency Analytics Plugin programmatically disables Content-Security-Policy protection for user-generated content when the 'Invoke Red Hat Dependency Analytics (RHDA)' build step is executed.
Recommendations For Jenkins Red Hat Dependency Analytics Plugin versions 0.7.1 and earlier, consider disabling the 'Invoke Red Hat Dependency Analytics (RHDA)' build step until a patch is available to prevent the disabling of Content-Security-Policy protection. Restrict access to user-generated content in workspaces and archived artifacts to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-02891
CVE-2024-23905
GHSA-X22X-5PP9-8V7F

Affected Products

Jenkins
Jenkins Red Hat Dependency Analytics Plugin
Red Os