GHSA-x22x-5pp9-8v7f
HIGHCVE-2024-23905Jenkins sets the Content-Security-Policy header to static files served by Jenkins (specifically DirectoryBrowserSupport), such as workspaces, /userContent, or archived artifacts, unless a Resource Root URL is specified.
- Affected
- < 0.9.0
- Fixed in
- 0.9.0
- Weakness
- CWE-79
- Published
- 2024-01-24
- Source
- github