Headline
GHSA-p2qq-c693-q53w: Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda_37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2024-52551
Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
High severity GitHub Reviewed Published Nov 13, 2024 to the GitHub Advisory Database • Updated Nov 14, 2024
Package
maven org.jenkinsci.plugins:pipeline-model-parent (Maven)
Affected versions
< 2.2218.v56d0cda
Patched versions
2.2218.v56d0cda
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda_37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-52551
- https://www.jenkins.io/security/advisory/2024-11-13/#SECURITY-3361
Published to the GitHub Advisory Database
Nov 13, 2024
Last updated
Nov 14, 2024