PT-2024-35373 · Jenkins · Jenkins Pipeline: Declarative Plugin+1

Kevin Guerroudj

·

Published

2024-11-13

·

Updated

2025-10-08

·

CVE-2024-52551

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Pipeline: Declarative Plugin versions 2.2214.vb b 34b 2ea 9b 83 and earlier
Description The issue allows attackers with Item/Build permission to restart a previous build whose Jenkinsfile script is no longer approved, as the plugin does not check whether the main script used to restart a build from a specific stage is approved. This can be exploited by attackers with the necessary permissions.
Recommendations For Jenkins Pipeline: Declarative Plugin versions 2.2214.vb b 34b 2ea 9b 83 and earlier, update to version 2.2218.v56d0cda 37c72 or later, which refuses to restart a build whose main Jenkinsfile script is unapproved. As a temporary workaround, consider restricting the Item/Build permission to minimize the risk of exploitation.

Fix

Improper Authorization

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-52551
GHSA-P2QQ-C693-Q53W
RHSA-2025:2218
RHSA-2025:2219
RHSA-2025:2220
RHSA-2025:2221
RHSA-2025:2222
RHSA-2025:2223

Affected Products

Jenkins
Jenkins Pipeline: Declarative Plugin