Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mrpr-vr82-x88r | Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin |
Fri, 10 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins pipeline\
|
|
| CPEs | cpe:2.3:a:jenkins:pipeline\:_groovy:*:*:*:*:*:jenkins:*:* cpe:2.3:a:jenkins:pipeline\:_groovy:3990.vd281dd77a_388:*:*:*:*:jenkins:*:* |
|
| Vendors & Products |
Jenkins pipeline\
|
Wed, 05 Mar 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ocp Tools |
|
| CPEs | cpe:/a:redhat:ocp_tools:4.12::el8 cpe:/a:redhat:ocp_tools:4.13::el8 cpe:/a:redhat:ocp_tools:4.14::el8 cpe:/a:redhat:ocp_tools:4.15::el8 cpe:/a:redhat:ocp_tools:4.16::el9 cpe:/a:redhat:ocp_tools:4.17::el9 |
|
| Vendors & Products |
Redhat
Redhat ocp Tools |
Tue, 26 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins groovy |
|
| Weaknesses | CWE-354 | |
| CPEs | cpe:2.3:a:jenkins:groovy:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins groovy |
|
| Metrics |
ssvc
|
Sat, 16 Nov 2024 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jenkins-plugin/workflow-cps: Lack of Approval Check for Rebuilt Jenkins Pipelines | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 13 Nov 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-26T14:45:03.205Z
Reserved: 2024-11-12T15:28:28.980Z
Link: CVE-2024-52550
Updated: 2024-11-13T21:26:57.212Z
Status : Analyzed
Published: 2024-11-13T21:15:29.293
Modified: 2025-10-10T15:29:56.260
Link: CVE-2024-52550
OpenCVE Enrichment
No data.
Github GHSA