Vulnerability Details CVE-2024-23905
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.8%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-23905
-
cpe:2.3:a:jenkins:red_hat_dependency_analytics:0.7.0
-
cpe:2.3:a:jenkins:red_hat_dependency_analytics:0.7.1