Логотип exploitDog
bind: "CVE-2024-47804"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-47804"

Количество 6

Количество 6

redhat логотип

CVE-2024-47804

9 месяцев назад

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-47804

9 месяцев назад

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-47804

9 месяцев назад

If an attempt is made to create an item of a type prohibited by `ACL#h ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f9qj-77q2-h5c5

9 месяцев назад

Jenkins item creation restriction bypass vulnerability

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2024-08496

9 месяцев назад

Уязвимость сервера автоматизации Jenkins, связанная с недостатками контроля доступа, позволяющая нарушителю обойти ограничения и создать временный элемент

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20241015-08

8 месяцев назад

Множественные уязвимости jenkins

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-47804

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2024-47804

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
debian логотип
CVE-2024-47804

If an attempt is made to create an item of a type prohibited by `ACL#h ...

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-f9qj-77q2-h5c5

Jenkins item creation restriction bypass vulnerability

CVSS3: 4.3
0%
Низкий
9 месяцев назад
fstec логотип
BDU:2024-08496

Уязвимость сервера автоматизации Jenkins, связанная с недостатками контроля доступа, позволяющая нарушителю обойти ограничения и создать временный элемент

CVSS3: 4.3
0%
Низкий
9 месяцев назад
redos логотип
ROS-20241015-08

Множественные уязвимости jenkins

CVSS3: 4.3
8 месяцев назад

Уязвимостей на страницу