First published: Wed Nov 13 2024(Updated: )
Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Pipeline | <3990.vd281dd77a_388>3975.3977.v478dd9e956c3<=3990.vd281dd77a_388 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2326043 is considered a critical vulnerability due to unauthorized access to unapproved Jenkinsfile scripts.
To fix REDHAT-BUG-2326043, upgrade the Jenkins Pipeline: Groovy Plugin to version 3990.vd281dd77a_389 or later.
Users of Jenkins Pipeline: Groovy Plugin versions up to 3990.vd281dd77a_388, who have Item/Build permissions, are affected by REDHAT-BUG-2326043.
Versions of Jenkins Pipeline: Groovy Plugin prior to 3990.vd281dd77a_389, specifically between 3975.3977.v478dd9e956c3 and 3990.vd281dd77a_388, are vulnerable.
REDHAT-BUG-2326043 exposes users to the risk of attackers rebuilding previous builds with unapproved scripts.