Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0958 | In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server. |
Github GHSA |
GHSA-m4rm-x2rr-357w | Jenkins Bitbucket Branch Source Plugin has incorrect trust policy behavior for pull requests |
Thu, 18 Sep 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins bitbucket Branch Source |
|
| CPEs | cpe:2.3:a:jenkins:bitbucket_branch_source:*:*:*:*:*:jenkins:*:* cpe:2.3:a:jenkins:bitbucket_branch_source:856.v04c46c86f911:*:*:*:*:jenkins:*:* cpe:2.3:a:jenkins:bitbucket_branch_source:866.vdea_7dcd3008e:*:*:*:*:jenkins:*:* |
|
| Vendors & Products |
Jenkins
Jenkins bitbucket Branch Source |
Thu, 07 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-281 | |
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-13T17:47:19.640Z
Reserved: 2024-03-05T19:29:05.204Z
Link: CVE-2024-28152
Updated: 2024-08-02T00:48:49.402Z
Status : Analyzed
Published: 2024-03-06T17:15:10.637
Modified: 2025-09-18T16:27:55.487
Link: CVE-2024-28152
OpenCVE Enrichment
No data.
EUVD
Github GHSA