Description
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fw9h-cxx9-gfq3 | Shared projects are unconditionally discovered by Jenkins GitLab Branch Source Plugin |
References
History
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-30T14:16:37.683Z
Reserved: 2024-01-23T12:46:51.264Z
Link: CVE-2024-23901
Updated: 2024-08-01T23:13:08.645Z
Status : Modified
Published: 2024-01-24T18:15:09.563
Modified: 2025-05-30T15:15:39.480
Link: CVE-2024-23901
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA