PT-2024-19236 · Jenkins · Jenkins Docker-Build-Step Plugin+1

Daniel Beck

·

Published

2024-03-06

·

Updated

2025-09-18

·

CVE-2024-2215

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Jenkins docker-build-step Plugin versions 2.11 and earlier
Description A cross-site request forgery issue allows attackers to connect to a specified TCP or Unix socket URL and reconfigure the plugin, affecting future build step executions.
Recommendations For Jenkins docker-build-step Plugin versions 2.11 and earlier, update to a version later than 2.11 to resolve the issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-2215
GHSA-64C5-R2H5-C2FG

Affected Products

Jenkins
Jenkins Docker-Build-Step Plugin