4.3

CVE-2024-52549

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Script Security SwPlatform jenkins Version < 1362.1364.v4cf2dc5d8776
Jenkins ≫ Script Security SwPlatform jenkins Version >= 1366.vd44b_49a_5c85c < 1367.vdf2fc45f229c
Jenkins ≫ Script Security Version 1365.v4778ca_84b_de5 SwPlatform jenkins
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.285
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://www.jenkins.io/security/advisory/2024-11-13/#SECURITY-3447
Vendor Advisory