6.3
CVE-2024-28152
- EPSS 0.03%
- Published 06.03.2024 17:15:10
- Last modified 18.09.2025 16:27:55
- Source jenkinsci-cert@googlegroups.co
- Teams watchlist Login
- Open Login
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.
Data is provided by the National Vulnerability Database (NVD)
Jenkins ≫ Bitbucket Branch Source SwPlatformjenkins Version < 848.850.v6a_a_2a_234a_c81
Jenkins ≫ Bitbucket Branch Source Version856.v04c46c86f911 SwPlatformjenkins
Jenkins ≫ Bitbucket Branch Source Version866.vdea_7dcd3008e SwPlatformjenkins
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.081 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.