VYPR
Moderate severityNVD Advisory· Published Mar 6, 2024· Updated Mar 25, 2025

CVE-2024-28153

CVE-2024-28153

Description

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:dependency-check-jenkins-pluginMaven
< 5.4.65.4.6

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

1