CVE-2024-23901
MEDIUMDescription
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group.
Is your site exposed to CVE-2024-23901?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| jenkins | github_branch_source |
References
Frequently Asked Questions
What is CVE-2024-23901? +
How severe is CVE-2024-23901? +
What products are affected by CVE-2024-23901? +
How do I check if I'm vulnerable to CVE-2024-23901? +
Related Vulnerabilities
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission …
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, …
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces …
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, …
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, …
In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of …