Loading HuntDB...

GHSA-x22x-5pp9-8v7f

GitHub Security Advisory

Content-Security-Policy disabled by Red Hat Dependency Analytics Jenkins Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins sets the Content-Security-Policy header to static files served by Jenkins (specifically DirectoryBrowserSupport), such as workspaces, /userContent, or archived artifacts, unless a Resource Root URL is specified.

Red Hat Dependency Analytics Plugin 0.7.1 and earlier globally disables the Content-Security-Policy header for static files served by Jenkins whenever the 'Invoke Red Hat Dependency Analytics (RHDA)' build step is executed. This allows cross-site scripting (XSS) attacks by users with the ability to control files in workspaces, archived artifacts, etc.

Affected Packages

Maven io.jenkins.plugins:redhat-dependency-analytics
Affected versions: 0 (fixed in 0.9.0)

Related CVEs

Key Information

GHSA ID
GHSA-x22x-5pp9-8v7f
Published
January 24, 2024 6:31 PM
Last Modified
January 29, 2024 9:54 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.jenkins.plugins:redhat-dependency-analytics
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.