Jenkins Pipeline: Declarative Plugin 2.2214.vbb34b2ea9b83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. This allows attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. Pipeline: Declarative Plugin 2.2218.v56d0cda37c72 refuses to restart a build whose main (Jenkinsfile) script is unapproved.
{
"cwe_ids": [
"CWE-276",
"CWE-285"
],
"severity": "HIGH",
"github_reviewed_at": "2024-11-14T15:43:58Z",
"nvd_published_at": "2024-11-13T21:15:29Z",
"github_reviewed": true
}