Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrpr-vr82-x88r

Опубликовано: 13 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.3
CVSS3: 8

Описание

Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Groovy Plugin 3993.v3e20a_37282f8 refuses to rebuild a build whose main (Jenkinsfile) script is unapproved.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-cps

maven
Затронутые версииВерсия исправления

< 3993.v3e20a

3993.v3e20a

EPSS

Процентиль: 77%
0.01035
Низкий

7.3 High

CVSS4

8 High

CVSS3

Дефекты

CWE-285
CWE-354

Связанные уязвимости

CVSS3: 8
redhat
около 1 года назад

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.

CVSS3: 8
nvd
около 1 года назад

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.

EPSS

Процентиль: 77%
0.01035
Низкий

7.3 High

CVSS4

8 High

CVSS3

Дефекты

CWE-285
CWE-354