Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28152

Опубликовано: 06 мар. 2024
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

A flaw was found in jenkins-2-plugins. Multibranch Pipelines with a Bitbucket branch source can be configured to discover pull requests from forks. The trust policy is set to "Forks in the same account" by default. In Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, this trust policy allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server. This allows attackers that are able to submit pull requests from forks to change the Pipeline behavior. In Bitbucket Branch Source Plugin 871.v28d74e8b_4226, the "Forks in the same account" trust policy does not extend trust to Jenkinsfiles modified by users without write access to the project.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-501
https://bugzilla.redhat.com/show_bug.cgi?id=2268226jenkins-2-plugins: Incorrect trust policy behavior for pull requests from forks in Bitbucket Branch Source Plugin

EPSS

Процентиль: 9%
0.00033
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
почти 2 года назад

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

CVSS3: 6.3
github
почти 2 года назад

Jenkins Bitbucket Branch Source Plugin has incorrect trust policy behavior for pull requests

EPSS

Процентиль: 9%
0.00033
Низкий

6.3 Medium

CVSS3