[JENKINS:SECURITY-3322] Content-Security-Policy protection for user content disabled by `redhat-dependency-analytics`

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Jenkins sets the Content-Security-Policy header to static files served by Jenkins (specifically DirectoryBrowserSupport), such as workspaces, /userContent, or archived artifacts, unless a Resource Root URL is specified.

redhat-dependency-analytics 0.7.1 and earlier globally disables the Content-Security-Policy header for static files served by Jenkins whenever the 'Invoke Red Hat Dependency Analytics (RHDA)' build step is executed.
This allows cross-site scripting (XSS) attacks by users with the ability to control files in workspaces, archived artifacts, etc.

NOTE: Jenkins instances with link:/doc/book/security/user-content/#resource-root-url[Resource Root URL] configured are unaffected.

redhat-dependency-analytics 0.9.0 does not disable the Content-Security-Policy header for static files served by Jenkins anymore.

ID
JENKINS:SECURITY-3322
Severity
high
Published
2024-01-24T00:00:00
(7 months ago)
Modified
2024-01-24T00:00:00
(7 months ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository redhat-dependency-analytics repository https://github.com/jenkinsci/redhat-dependency-analytics-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/redhat-dependency-analytics org.jenkins-ci.plugins redhat-dependency-analytics <= 0.7.1
Fixed pkg:maven/org.jenkins-ci.plugins/redhat-dependency-analytics org.jenkins-ci.plugins redhat-dependency-analytics = 0.9.0
Affected pkg:github/jenkinsci/redhat-dependency-analytics-plugin jenkinsci redhat-dependency-analytics-plugin <= 0.7.1
Fixed pkg:github/jenkinsci/redhat-dependency-analytics-plugin jenkinsci redhat-dependency-analytics-plugin = 0.9.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...