CVE Published: 24/01/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Red Hat Dependency Analytics Plugin Status : PUBLISHED
CVE-2024-23905 Description
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.