Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-52550


Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.


Published

2024-11-13T21:15:29.293

Last Modified

2025-10-10T15:29:56.260

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-354

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins pipeline\ < 3975.3977.v478dd9e956c3 Yes
Application jenkins pipeline\ _groovy Yes

References