Impact
The Jenkins OWASP Dependency‑Check Plugin, versions 5.6.4 and earlier, fails to escape CWE identifiers that appear in Dependency‑Check reports when they are displayed on the Jenkins user interface. Because the uncoded values are rendered directly into HTML, a malicious actor who can add a configuration item can inject JavaScript that will run in the browser of any user who views the affected job page. The vulnerability enables stored cross‑site scripting; it can lead to session hijacking, defacement, or credential theft for users with browser access to the Jenkins instance.
Affected Systems
The affected product is the Jenkins OWASP Dependency‑Check Plugin for the Jenkins Project. The flaw exists in plugin releases 5.6.4 and earlier. Any Jenkins installation that has those plugin versions installed, regardless of Jenkins core version, is at risk. The vulnerability is specific to jobs and items where users have Item/Configure permission, but affected configuration pages can be accessed by any user who can view the job.
Risk and Exploitability
The severity of the issue is reflected in a CVSS score of 8, indicating high impact. The EPSS score is below 1 percent, suggesting a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers still need the Item/Configure right to inject the malicious payload, so the attack vector is internal or requires privileged access. Once injected, the payload is executed in the victim’s browser, giving the attacker persistence and the ability to steal credentials or perform other client‑side attacks.
OpenCVE Enrichment