PT-2024-35372 · Jenkins · Jenkins Pipeline: Groovy Plugin+1

Kevin Guerroudj

·

Published

2024-11-13

·

Updated

2025-10-10

·

CVE-2024-52550

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Pipeline: Groovy Plugin versions 3990.vd281dd77a 388 and earlier, except version 3975.3977.v478dd9e956c3
Description The issue allows attackers with Item/Build permission to rebuild a previous build whose Jenkinsfile script is no longer approved, because the main script for a rebuilt build is not checked for approval. This can be exploited by attackers with the necessary permissions to rebuild previous builds with unapproved scripts.
Recommendations For versions 3990.vd281dd77a 388 and earlier, except version 3975.3977.v478dd9e956c3, update to a version that includes the fix, such as version 3993.v3e20a 37282f8, which refuses to rebuild a build whose main Jenkinsfile script is unapproved. At the moment, there is no other information about additional mitigation measures.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-52550
GHSA-MRPR-VR82-X88R
RHSA-2025:2218
RHSA-2025:2219
RHSA-2025:2220
RHSA-2025:2221
RHSA-2025:2222
RHSA-2025:2223

Affected Products

Jenkins
Jenkins Pipeline: Groovy Plugin