CVE-2024-52554
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2024
Last modified:
03/10/2025
Description
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:shared_library_version_override:*:*:*:*:*:jenkins:*:* | 17.v786074c9fce7 (including) |
To consult the complete list of CPE names with products and versions, see this page



