GHSA-7845-crfj-phc4

Suggest an improvement
Source
https://github.com/advisories/GHSA-7845-crfj-phc4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-7845-crfj-phc4/GHSA-7845-crfj-phc4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7845-crfj-phc4
Aliases
  • CVE-2024-52554
Published
2024-11-13T21:30:38Z
Modified
2024-11-14T16:12:43.663565Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin
Details

Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection. This allows attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection. Shared Library Version Override Plugin 19.v3ac975738d4a declares folder-scoped library overrides as untrusted, so that they’re executed in the Script Security sandbox.

References

Affected packages

Maven / io.jenkins.plugins:shared-library-version-override

Package

Name
io.jenkins.plugins:shared-library-version-override
View open source insights on deps.dev
Purl
pkg:maven/io.jenkins.plugins/shared-library-version-override

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
19.v3a

Affected versions

11.*

11.v1ee70e324a_3f

17.*

17.v786074c9fce7