Improper access control in Red Hat Dependency Analytics - CVE-2024-23905
Published: January 25, 2024
Red Hat Dependency Analytics
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin globally disables the Content-Security-Policy header for static files served by Jenkins whenever the "Invoke Red Hat Dependency Analytics (RHDA)" build step is executed. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.