Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Mar 2025 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat ocp Tools |
|
CPEs | cpe:/a:redhat:ocp_tools:4.12::el8 cpe:/a:redhat:ocp_tools:4.13::el8 cpe:/a:redhat:ocp_tools:4.14::el8 cpe:/a:redhat:ocp_tools:4.15::el8 cpe:/a:redhat:ocp_tools:4.16::el9 cpe:/a:redhat:ocp_tools:4.17::el9 |
|
Vendors & Products |
Redhat
Redhat ocp Tools |
Fri, 22 Nov 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | jenkins-plugin/script-security: Jenkins Script Security Plugin File Disclosure Vulnerability | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 13 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 | |
Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-13T21:35:30.700Z
Reserved: 2024-11-12T15:28:28.980Z
Link: CVE-2024-52549

Updated: 2024-11-13T21:35:23.410Z

Status : Awaiting Analysis
Published: 2024-11-13T21:15:29.233
Modified: 2024-11-15T14:00:09.720
Link: CVE-2024-52549
