Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2qq-c693-q53w

Опубликовано: 13 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda_37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.

Пакеты

Наименование

org.jenkinsci.plugins:pipeline-model-parent

maven
Затронутые версииВерсия исправления

< 2.2218.v56d0cda

2.2218.v56d0cda

EPSS

Процентиль: 43%
0.00209
Низкий

8 High

CVSS3

Дефекты

CWE-276
CWE-285

Связанные уязвимости

CVSS3: 8
redhat
около 1 года назад

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.

CVSS3: 8
nvd
около 1 года назад

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.

EPSS

Процентиль: 43%
0.00209
Низкий

8 High

CVSS3

Дефекты

CWE-276
CWE-285