CVE-2024-28152
Last modified
CVE-2024-28152 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Bitbucket Branch Source | < 848.850.v6a_a_2a_234a_c81 |
| Jenkins | Bitbucket Branch Source | 856.v04c46c86f911 |
| Jenkins | Bitbucket Branch Source | 866.vdea_7dcd3008e |
References
- http://www.openwall.com/lists/oss-security/2024/03/06/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/06/3Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-28152?
How severe is CVE-2024-28152?
How do I fix CVE-2024-28152?
Are you affected by CVE-2024-28152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
