CVE-2024-28153

Name
CVE-2024-28153
Description
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://www.jenkins.io/security/advisory/2024-03-06/#SECURITY-3344
jenkinsci-cert@googlegroups.com http://www.openwall.com/lists/oss-security/2024/03/06/3

Match rules

CPE URI Source package Min version Max version
jenkins-owasp-dependency-check-plugin >= 0 <= 5.4.5
cpe:2.3:a:jenkins:owasp_dependency-check:*:*:*:*:*:jenkins:*:* jenkins >= None < 5.4.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
jenkins edge-community 2.479.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.479.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.516.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.22-community 2.479.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.22-community 2.479.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable