PT-2024-2759 · Red Hat+2 · Jenkins Red Hat Dependency Analytics Plugin+2
Pierre Beitz
·
Published
2024-01-24
·
Updated
2024-04-11
·
CVE-2024-23905
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Red Hat Dependency Analytics Plugin versions 0.7.1 and earlier
Description
The issue is related to the lack of Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. This allows a remote attacker to perform cross-site scripting (XSS) attacks with the possibility of managing files in workspaces. The Red Hat Dependency Analytics Plugin programmatically disables Content-Security-Policy protection for user-generated content when the 'Invoke Red Hat Dependency Analytics (RHDA)' build step is executed.
Recommendations
For Jenkins Red Hat Dependency Analytics Plugin versions 0.7.1 and earlier, consider disabling the 'Invoke Red Hat Dependency Analytics (RHDA)' build step until a patch is available to prevent the disabling of Content-Security-Policy protection. Restrict access to user-generated content in workspaces and archived artifacts to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Red Hat Dependency Analytics Plugin
Red Os