Description
Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
Published: 2024-11-13
Score: 8 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mrpr-vr82-x88r Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin
History

Fri, 10 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins pipeline\
CPEs cpe:2.3:a:jenkins:pipeline\:_groovy:*:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:pipeline\:_groovy:3990.vd281dd77a_388:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins pipeline\

Wed, 05 Mar 2025 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ocp Tools
CPEs cpe:/a:redhat:ocp_tools:4.12::el8
cpe:/a:redhat:ocp_tools:4.13::el8
cpe:/a:redhat:ocp_tools:4.14::el8
cpe:/a:redhat:ocp_tools:4.15::el8
cpe:/a:redhat:ocp_tools:4.16::el9
cpe:/a:redhat:ocp_tools:4.17::el9
Vendors & Products Redhat
Redhat ocp Tools

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins groovy
Weaknesses CWE-354
CPEs cpe:2.3:a:jenkins:groovy:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins groovy
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 16 Nov 2024 02:00:00 +0000

Type Values Removed Values Added
Title jenkins-plugin/workflow-cps: Lack of Approval Check for Rebuilt Jenkins Pipelines
Weaknesses CWE-862
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 13 Nov 2024 21:00:00 +0000

Type Values Removed Values Added
Description Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
References

Subscriptions

Jenkins Groovy Pipeline\
Redhat Ocp Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-11-26T14:45:03.205Z

Reserved: 2024-11-12T15:28:28.980Z

Link: CVE-2024-52550

cve-icon Vulnrichment

Updated: 2024-11-13T21:26:57.212Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-13T21:15:29.293

Modified: 2025-10-10T15:29:56.260

Link: CVE-2024-52550

cve-icon Redhat

Severity : Important

Publid Date: 2024-11-13T20:53:00Z

Links: CVE-2024-52550 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses