CVE-2024-52551

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.
Configurations

No configuration.

History

14 Nov 2024, 15:35

Type Values Removed Values Added
Summary
  • (es) Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 y anteriores no verifica si el script principal (Jenkinsfile) utilizado para reiniciar una compilación desde una etapa específica está aprobado, lo que permite a los atacantes con permiso de Elemento/Compilación reiniciar una compilación anterior cuyo script (Jenkinsfile) ya no está aprobado.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-276

13 Nov 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 21:15

Updated : 2024-11-15 14:00


NVD link : CVE-2024-52551

Mitre link : CVE-2024-52551

CVE.ORG link : CVE-2024-52551


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions