Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.

Project Subscriptions

Vendors Products
Jenkins Subscribe
Pipeline\ Subscribe
Jenkins Project Subscribe
Jenkins Pipeline Declaratrive Plugin Subscribe
Ocp Tools Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p2qq-c693-q53w Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Oct 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins pipeline\
CPEs cpe:2.3:a:jenkins:pipeline\:_declarative:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins pipeline\

Wed, 05 Mar 2025 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ocp Tools
CPEs cpe:/a:redhat:ocp_tools:4.12::el8
cpe:/a:redhat:ocp_tools:4.13::el8
cpe:/a:redhat:ocp_tools:4.14::el8
cpe:/a:redhat:ocp_tools:4.15::el8
cpe:/a:redhat:ocp_tools:4.16::el9
cpe:/a:redhat:ocp_tools:4.17::el9
Vendors & Products Redhat
Redhat ocp Tools

Sat, 16 Nov 2024 02:00:00 +0000

Type Values Removed Values Added
Title jenkins-plugin/pipeline-model-definition: Jenkins Pipeline Declarative Plugin Allows Restart of Builds with Unapproved Jenkinsfile
Weaknesses CWE-862
References
Metrics threat_severity

None

threat_severity

Important


Thu, 14 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Pipeline Declaratrive Plugin
Weaknesses CWE-276
CPEs cpe:2.3:a:jenkins_project:jenkins_pipeline_declaratrive_plugin:*:*:*:*:*:*:*:*
Vendors & Products Jenkins Project
Jenkins Project jenkins Pipeline Declaratrive Plugin
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 21:00:00 +0000

Type Values Removed Values Added
Description Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-11-14T15:05:27.789Z

Reserved: 2024-11-12T15:28:28.980Z

Link: CVE-2024-52551

cve-icon Vulnrichment

Updated: 2024-11-14T15:05:21.271Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-13T21:15:29.350

Modified: 2025-10-08T20:39:41.427

Link: CVE-2024-52551

cve-icon Redhat

Severity : Important

Publid Date: 2024-11-13T20:53:01Z

Links: CVE-2024-52551 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses