REDHAT-BUG-2326043: High severity jenkins pipeline vulnerability
Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2326043?
REDHAT-BUG-2326043 is considered a critical vulnerability due to unauthorized access to unapproved Jenkinsfile scripts.
How do I fix REDHAT-BUG-2326043?
To fix REDHAT-BUG-2326043, upgrade the Jenkins Pipeline: Groovy Plugin to version 3990.vd281dd77a_389 or later.
Who is affected by REDHAT-BUG-2326043?
Users of Jenkins Pipeline: Groovy Plugin versions up to 3990.vd281dd77a_388, who have Item/Build permissions, are affected by REDHAT-BUG-2326043.
What versions of Jenkins Pipeline are vulnerable in REDHAT-BUG-2326043?
Versions of Jenkins Pipeline: Groovy Plugin prior to 3990.vd281dd77a_389, specifically between 3975.3977.v478dd9e956c3 and 3990.vd281dd77a_388, are vulnerable.
What does REDHAT-BUG-2326043 expose users to?
REDHAT-BUG-2326043 exposes users to the risk of attackers rebuilding previous builds with unapproved scripts.