CVE-2024-52554

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2024
Last modified:
03/10/2025

Description

Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:shared_library_version_override:*:*:*:*:*:jenkins:*:* 17.v786074c9fce7 (including)


References to Advisories, Solutions, and Tools