Database/Control plane, storage & DevOps
Jenkins OWASP Dependency-Check Plugin: CWE values from reports are rendered unescaped, giving stored XSS
Impact
Dependency-Check Plugin 5.6.4 and earlier renders CWE values taken from Dependency-Check reports into the Jenkins UI without escaping them. An attacker with Item/Configure permission can arrange for a report containing script in a CWE field, which then executes in the browser of any user who views the report - typically a build owner or administrator, with their Jenkins session. Because the payload arrives through report data rather than through a configuration field, it can ride in on scan output rather than requiring a visibly malicious job setting.
Who can reach it
An authenticated Jenkins user with Item/Configure permission who can influence the Dependency-Check report a job publishes; a second user must view the report page.
What to do
Update the OWASP Dependency-Check Plugin past 5.6.4 via the update center and restart the Jenkins controller. Controller-only maintenance; agents and GPU nodes are unaffected. Until then, limit Item/Configure permission and treat Dependency-Check report pages from untrusted jobs as untrusted content.
References
Related entries
- IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeCVE-2022-41739 · IBM Spectrum Scale / Storage Scale Container Native Storage AccessHigh
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalCVE-2026-72312 · Linux octeontx2-af (VF rx-mode affecting PF promiscuous state)High
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
- IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumCVE-2018-1431 · IBM Spectrum Scale daemon (GSKit cryptographic library dependency)High
- Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughCVE-2019-18181 · Arista CloudVision Portal (Configlet Builder API)High
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsCVE-2019-3691 · MUNGE (SUSE/openSUSE packaging)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.